PRIVACY POLICY

IDEOGEN Group GmbH Version 2.0 | March 2026

Table of Contents

  • Controller Identity & Contact
  • Scope of This Policy
  • Categories of Personal Data We Collect
  • Purposes of Processing
  • Legal Bases for Processing
  • Recipients and Data Sharing
  • International Data Transfers
  • Data Retention Periods
  • Your Rights as a Data Subject
  • Automated Decision-Making and Profiling
  • Cookies and Tracking Technologies
  • Children
  • Security Measures
  • Pharmacovigilance — Special Provisions
  • Changes to This Policy
  • Contact and Complaints

1. Controller Identity & Contact

The data controller responsible for the processing of your personal data in connection with our website and digital services is:

IDEOGEN Group GmbH Hurdnerstrasse 119 CH-8640 Hurden SZ Switzerland

Telephone: +41 43 311 52 52 General enquiries: [email protected] Healthcare / medical information: [email protected] Website: www.ideogen.com

Data Protection Officer (DPO): [Name to be appointed] [email protected] IDEOGEN Group GmbH, Hurdnerstrasse 119, CH-8640 Hurden SZ, Switzerland

Where IDEOGEN Group GmbH's subsidiaries or affiliates (listed in Section 6 below) act as independent controllers in connection with their respective local operations, they remain individually responsible for their own data processing activities. For all website-related processing and group-wide digital touchpoints, IDEOGEN Group GmbH is the sole controller.

2. Scope of This Policy

This Privacy Policy applies to all personal data processed by IDEOGEN Group GmbH ("IDEOGEN," "we," "us," "our") in connection with:

  • The public website at www.ideogen.com, including all language variants (EN, FR, DE, IT) and subpages;
  • The IDEOGEN Partner Platform (login-required portal for order placement, medicine tracking, and partner account management);
  • All digital touchpoints operated by IDEOGEN, including contact forms, medical information request forms, pharmacovigilance / adverse event reporting forms, and recruitment submission portals;
  • Email, telephone, and other communications initiated via or in connection with the above channels.

This Policy does not apply to third-party websites linked from www.ideogen.com. We encourage you to review the privacy notices of any third-party sites you visit.

3. Categories of Personal Data We Collect

Depending on how you interact with our website and services, we may process the following categories of personal data:

3.1 Contact Data

Name, job title, organisation, business postal address, business email address, business telephone number, and any other information you voluntarily provide in a contact form or enquiry.

3.2 Professional / Healthcare Professional (HCP) Data

Healthcare professional registration numbers, prescriber licence information, medical speciality, institutional affiliation, and purchasing authority credentials, where provided for the purpose of partner onboarding or medical information requests.

3.3 Health and Medical Data (Special Category)

Personal data relating to health conditions, adverse events, suspected adverse reactions to medicinal products, concomitant medications, patient demographics (including age, sex, and medical history) submitted as part of a pharmacovigilance (PV) report or a medical information inquiry. This data is classified as special category data under and sensitive personal data under and is subject to heightened safeguards.

3.4 Usage and Technical Data

IP address (truncated where technically possible), browser type and version, operating system, device type, referral URL, pages visited, time and duration of visit, click-stream data, and server log files generated automatically when you access www.ideogen.com or the Partner Platform.

3.5 Cookie and Tracking Data

Data collected through cookies, web beacons, pixels, and similar technologies as further described in our Cookie Policy. This includes analytics identifiers (e.g., Google Analytics Client ID), session tokens, language preference tokens, and consent preference records. See Section 11 and our separate Cookie Policy for full details.

3.6 Partner Platform Data

For registered partners (distributors, healthcare institutions, licensed importers), we process: account credentials (username, contact person details), order history, shipment tracking information, medicine tracker data (product identifiers, batch numbers, quantities), contractual correspondence, and invoicing data.

3.7 Recruitment Data

CVs/résumés, cover letters, qualifications, professional licences, references, and any other information submitted through our careers page or directly to our recruitment team.

3.8 Consent Records

Records of your consent or objection to any processing activity for which consent is the applicable legal basis, including the timestamp, version of notice presented, and the scope of consent given.

4. Purposes of Processing

We process personal data for the following purposes:

5. Legal Bases for Processing

We process personal data only where we have a valid legal basis. The following table maps each processing purpose to the applicable legal basis under the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP/nDSG), effective 1 September 2023.

Special Category Data (Health / PV Data)

Where we process health data (Section 3.3) in the context of pharmacovigilance or medical information requests, we rely additionally on:

  • ** Processing necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of medicinal products.
  • **Swiss nFADP Article 5**: Processing of sensitive personal data is permitted where it is necessary for an overriding public interest, specifically the monitoring of the safety and efficacy of medicinal products.

6. Recipients and Data Sharing

We do not sell your personal data. We share personal data with third parties only as described below and, where required, subject to appropriate data processing agreements (DPAs) under equivalent contractual safeguards under Swiss .

6.1 IDEOGEN Group Companies

Personal data may be shared among IDEOGEN Group entities for internal administrative purposes, shared IT systems, and coordinated partner servicing. Group entities are:

Intra-group transfers are governed by intra-group data transfer agreements and, where applicable, Standard Contractual Clauses.

6.2 Pharmacovigilance Service Provider

APCER Life Sciences (apcerls.com) processes pharmacovigilance data on our behalf as a GDPR Article 28 data processor. APCER receives Individual Case Safety Reports (ICSRs) submitted to IDEOGEN and fulfils signal detection, case management, PSUR preparation, and regulatory reporting obligations. Contact for PV matters: [email protected], +44 746 858 28 32.

6.3 Regulatory and Health Authorities

In fulfilment of our legal obligations, PV data and, where legally required, other data may be reported to:

  • **** (Swiss Agency for Therapeutic Products)
  • ** (EMA)**
  • National competent authorities of EEA member states
  • National competent authorities in countries where our products are authorised or under managed access programs (including, but not limited to, Turkey TITCK, MENA region authorities, CIS region authorities)
  • **** (Federal Data Protection and Information Commissioner, Switzerland) upon lawful request

6.4 IT Service Providers and Hosting

Our website and Partner Platform are hosted by IT infrastructure and cloud service providers who process data as processors under binding DPAs. We use providers with data centres located in Switzerland and/or the EEA, or providers covered by adequate transfer mechanisms.

6.5 Analytics Providers

Google Analytics (Google LLC / Google Ireland Limited) receives usage and cookie data as described in Section 3.5 and Section 7.2. Data is processed under Google's Data Processing Terms and applicable Standard Contractual Clauses.

6.6 Professional Advisers

Legal counsel, auditors, insurers, and accountants may access personal data to the extent necessary to provide their professional services. These parties are bound by confidentiality obligations.

6.7 Corporate Transactions

In the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the prospective or actual successor entity, subject to equivalent data protection commitments.

7. International Data Transfers

IDEOGEN processes data and shares data with recipients in countries both inside and outside the European Economic Area (EEA) and Switzerland. We ensure appropriate safeguards are in place for all international transfers.

7.1 Switzerland–EU Mutual Adequacy

Switzerland has been recognised by the European Commission as providing an adequate level of data protection (Commission Decision of 26 July 2000, as updated). The Swiss , in turn, recognises the EEA as providing adequate protection. Accordingly, transfers of personal data between IDEOGEN Group GmbH (Switzerland) and IDEOGEN's EU/EEA subsidiaries in the Netherlands, Spain, Austria, and Malta do not require additional safeguards beyond internal governance measures.

7.2 Google Analytics — United States

Data transferred to Google LLC (United States) in connection with Google Analytics is governed by the EU–U.S. Data Privacy Framework (DPF) (where applicable) and the EU Standard Contractual Clauses (2021) (Module 2: Controller to Processor), supplemented by a Transfer Impact Assessment. Switzerland-originating data to the United States is covered by the applicable SCCs with Swiss-specific addenda reflecting nFADP requirements and the FDPIC's position on cross-border transfers (Art. 16–19 nFADP).

7.3 Standard Contractual Clauses (SCCs)

For transfers to countries not covered by an adequacy decision, we rely on the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (June 2021), in their applicable module configurations. For transfers from Switzerland, we use the SCCs as supplemented by a Swiss-specific addendum in accordance with the FDPIC's guidance and the requirements of nFADP Articles 16–19 and 25.

7.4 Turkey

Personal data transferred to our Turkish office is subject to SCCs and internal data transfer agreements. Turkey is not currently on the FDPIC's list of countries with adequate protection; accordingly, standard contractual clauses and supplementary measures are applied, including encryption in transit and at rest and data minimisation.

7.5 MENA and CIS Regions

Where operational requirements necessitate data sharing with business partners or regulatory authorities in MENA or CIS countries, we apply data minimisation, pseudonymisation where practicable, and contractual safeguards. Regulatory reporting obligations (e.g., adverse event reporting) constitute a legal obligation that overrides standard transfer restrictions to the extent strictly necessary for compliance.

7.6 Right to Information

You may request information about the specific safeguards applied to a transfer of your personal data by contacting [email protected].

8. Data Retention Periods

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The following table sets out our standard retention periods:

At the end of each applicable retention period, personal data is either securely deleted, anonymised (where anonymisation is technically verifiable and irreversible), or, in the case of PV data, archived in a manner that continues to fulfil regulatory traceability requirements.

9. Your Rights as a Data Subject

Depending on your location and applicable law, you have the following rights with respect to the personal data we hold about you. You may exercise any of these rights by contacting [email protected] or using the contact details in Section 16.

Rights under both GDPR and Swiss nFADP

9.1 Right of Access

You have the right to obtain confirmation as to whether we process personal data about you and, if so, to receive a copy of that data together with information about the purposes, categories of data, recipients, retention periods, and the existence of automated decision-making (; ).

9.2 Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data (;

9.3 Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal data where: the data is no longer necessary for the purposes for which it was collected; you withdraw consent and there is no other legal basis; you object and there are no overriding legitimate interests; or the data has been unlawfully processed (; nFADP Art. 32(2)).

This right does not apply where retention is required by law (e.g., PV data, commercial records) or where the data is necessary for the establishment, exercise, or defence of legal claims. See Section 8 for applicable retention periods and Section 14 for PV-specific limitations.

9.4 Right to Restriction of Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances: where you contest the accuracy of the data; where processing is unlawful but you oppose erasure; where we no longer need the data but you require it for legal claims; or where you have objected pending verification of our legitimate interests (; nFADP Art. 32(3)).

9.5 Right to Data Portability

Where processing is based on your consent or on the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller (; right to data disclosure in interoperable format).

9.6 Right to Object

You have the right to object at any time to processing of your personal data based on legitimate interests ( or for direct marketing purposes. Where you object to direct marketing, we will cease processing immediately. For other objections, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests or the processing is necessary for legal claims (;

9.7 Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal ( To withdraw consent for marketing communications, use the unsubscribe link in any marketing email or contact [email protected]. To withdraw cookie consent, access your consent preferences via the consent banner or cookie settings tool on our website.

9.8 Rights in Relation to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or significantly affects you (; ). See Section 10 for our current practice.

9.9 Right to Lodge a Complaint with a Supervisory Authority

Switzerland: You may lodge a complaint with the ** (FDPIC)**: Feldeggweg 1 3003 Bern, Switzerland Tel: +41 58 462 43 95 Website: www.edoeb.admin.ch

EU/EEA: If you are located in an EU member state, you may lodge a complaint with the data protection supervisory authority of your country of habitual residence, place of work, or the place of the alleged infringement. Key authorities include:

  • Autoriteit Persoonsgegevens (Netherlands): autoriteitpersoonsgegevens.nl
  • Agencia Española de Protección de Datos (AEPD) (Spain): aepd.es
  • Datenschutzbehörde (DSB) (Austria): dsb.gv.at

We would, however, appreciate the opportunity to address your concerns before you contact a supervisory authority.

10. Automated Decision-Making and Profiling

IDEOGEN does not currently use automated decision-making processes, including profiling, that produce legal effects or similarly significantly affect individuals as described in and .

Our analytics tools (including Google Analytics) generate aggregated statistical data about website usage. This is used for aggregate trend analysis only and does not result in individual decisions with legal or similarly significant effects.

Should we introduce any automated decision-making in the future, we will update this Policy and, where required, conduct a Data Protection Impact Assessment (DPIA) in accordance with .

11. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on www.ideogen.com and the Partner Platform. A full description of the cookies we use, their purposes, durations, and your consent choices is set out in our separate [Cookie Policy], which forms part of this Privacy Policy.

In summary:

  • Strictly necessary cookies are placed without consent as they are essential for the operation of the website.
  • Analytics and marketing cookies are placed only with your prior, freely given, specific, and informed consent via our Consent Management Platform (CMP) banner.
  • You may update your consent choices at any time by clicking the cookie settings link in the footer of our website.

The legal bases applicable to cookie-based processing are described in Section 5 above (purposes P7 and P6) and in the Cookie Policy.

12. Children

Our website and services are directed at adults and healthcare and pharmaceutical professionals. We do not knowingly collect personal data from children under the age of 16. If you are under 16, please do not submit any personal data to us.

If we become aware that we have collected personal data from a child under 16 without verified parental consent, we will take steps to delete that data as promptly as possible. If you believe we may have collected data from a child under 16, please notify us at [email protected].

13. Security Measures

IDEOGEN implements appropriate technical and organisational measures (TOMs) to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, in accordance with .

Our security measures include, but are not limited to:

  • Encryption: Data in transit is encrypted using TLS 1.2 or higher; sensitive data at rest is encrypted using AES-256 or equivalent industry-standard encryption.
  • Access controls: Role-based access controls (RBAC) are applied to all systems holding personal data; access is granted on a need-to-know basis. Access to health and PV data is restricted to authorised personnel only.
  • Pseudonymisation: Where technically feasible and appropriate (particularly for analytics data), we apply pseudonymisation to reduce re-identification risk.
  • Regular audits and penetration testing: Our IT infrastructure and data processing systems are subject to periodic security assessments, vulnerability scans, and penetration tests.
  • Incident response procedures: We maintain documented data breach response procedures, including a protocol for notifying the within 72 hours of becoming aware of a reportable breach (; ).
  • Data Processing Agreements: All processors and sub-processors handling personal data on our behalf are subject to written DPAs incorporating /
  • Staff training: All IDEOGEN staff with access to personal data receive regular data protection training.
  • Physical security: Physical access to server infrastructure and office premises where personal data is handled is restricted and monitored.

Notwithstanding the above measures, no method of transmission over the Internet or electronic storage is 100% secure. If you have reason to believe your personal data has been compromised, please contact [email protected] immediately.

14. Pharmacovigilance — Special Provisions

14.1 Why We Must Process Health Data for Pharmacovigilance

IDEOGEN, as a marketing authorisation holder (MAH) and licensed importer/distributor of medicinal products, is subject to mandatory pharmacovigilance (PV) obligations under:

  • Swiss Therapeutic Products Act (TPA/HMG), in particular Articles 59 and 66, and applicable ordinances;
  • **EU , Title IX (Pharmacovigilance), as amended by **;
  • **** on pharmacovigilance for human medicinal products;
  • ** (GVP)**, in particular GVP Module VI (Management and Reporting of Adverse Reactions to Medicinal Products);
  • For Advanced Therapy Medicinal Products (ATMPs): ****.

These legal obligations require us to collect, evaluate, document, and report information about suspected adverse reactions to medicinal products, regardless of whether the affected individual has consented to such reporting. This processing cannot be declined by data subjects and does not rely on consent as its legal basis.

14.2 Legal Basis

Processing of personal health data for PV purposes is based on:

  • ** — legal obligation;
  • ** — public interest in the area of public health;
  • **Swiss — legal obligation;
  • **Swiss ** — overriding public interest (sensitive personal data).

14.3 Data Sharing for PV Purposes

IDEOGEN transmits Individual Case Safety Reports (ICSRs) and periodic safety update reports (PSURs) to:

  • **Swissmedic** (Switzerland) via the designated national reporting system;
  • EudraVigilance ( database) for products with EU marketing authorisations;
  • National competent authorities in all countries where our products are authorised or distributed, including authorities in Turkey, MENA, and CIS regions where applicable local reporting obligations exist;
  • APCER Life Sciences (our contracted PV service provider), which processes PV data strictly as a data processor under a binding DPA.

All ICSRs are pseudonymised at source to the extent required by GVP Module VI and applicable authority guidance, with identifying data retained only where traceability obligations require it.

14.4 Retention of PV Data

  • Standard medicinal products: Minimum 10 years from expiry of marketing authorisation or product discontinuation;
  • ATMPs, cell therapies, blood/plasma products: Minimum 30 years (Regulation (EC) No 1394/2007; Directive 2002/98/EC);
  • Safety-critical records may be retained for longer periods where required by specific regulatory guidance or ongoing signal investigations.

14.5 Your Rights in Relation to PV Data

In accordance with GVP Module VI and applicable data protection law, the right to erasure (Section 9.3) and the right to object (Section 9.6) do not apply to personal data processed for pharmacovigilance purposes to the extent that such processing is required by law. You retain the rights of access (Section 9.1), rectification (Section 9.2), and restriction (Section 9.4) subject to the constraints imposed by applicable PV regulations.

15. Changes to This Policy

We review this Privacy Policy periodically and update it to reflect changes in our data processing activities, applicable law, or regulatory guidance.

When we make material changes, we will:

  • Update the "Version" and "Date" indicated at the top of this Policy;
  • Post the revised Policy on www.ideogen.com/privacy-policy with a prominent notice indicating that the Policy has been updated;
  • Where we have your contact details and the changes materially affect how we process your personal data, notify you by email within a reasonable period prior to the changes taking effect.

Your continued use of our website and services after the effective date of the updated Policy constitutes acknowledgement of the changes. For consent-based processing, we will obtain fresh consent where legally required.

Prior versions of this Policy are available upon request from [email protected].

16. Contact and Complaints

For any questions, concerns, or to exercise your data subject rights, please contact:

Data Protection Officer [Name to be appointed] [email protected] IDEOGEN Group GmbH Hurdnerstrasse 119 CH-8640 Hurden SZ Switzerland

General Privacy Enquiries [email protected]

Healthcare / Medical Information [email protected]

For pharmacovigilance / adverse event reporting, please use the dedicated form at www.ideogen.com/report-form or contact APCER Life Sciences directly at [email protected] / +44 746 858 28 32.

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority:

Switzerland — FDPIC: (FDPIC) Feldeggweg 1 3003 Bern Tel: +41 58 462 43 95 www.edoeb.admin.ch

Netherlands — AP: Autoriteit Persoonsgegevens www.autoriteitpersoonsgegevens.nl

Spain — AEPD: Agencia Española de Protección de Datos www.aepd.es

Austria — DSB: Datenschutzbehörde www.dsb.gv.at

This Privacy Policy was last revised in March 2026 (Version 2.0). IDEOGEN Group GmbH, Hurdnerstrasse 119, CH-8640 Hurden SZ, Switzerland.