Data privacy policy
Last update: August 2026
Version: 2.0
This Policy may be modified by SERVIER, particularly to take into account changes in applicable law and our activities. Any changes will be posted on this page, which we invite you to consult regularly.
Purpose of this Data Privacy Policy (the “Policy”): This Policy is intended to provide clear and transparent information on how personal data is processed within the framework of the use of the website Homepage – Institut Servier.
This Policy does not describe the processing carried out via the cookies used on our website. For more information, please consult our Cookies Policy.
1. Who is the Data Controller?
The Servier Group is made up of several entities. The Servier entity acting as data controller may differ depending on the purpose pursued.
The Servier entity acting as data controller is indicated in the table below.
2. Why do we collect personal data and on which basis? Which data are we talking about?
This Policy describes activities for which we need to use personal data, according to the appropriate legal basis.
We only use data that is strictly necessary for the purposes we are pursuing. Fields marked with an asterisk are mandatory. Failure to provide this information will prevent us from processing your request.
| Data controller entity | Purpose pursued | Data collected | Legal basis of processing |
|---|---|---|---|
| L’Institut Servier 50, rue Carnot 92284 SURESNES Cedex, France | Management of requests relating to another subject | Identification data that we need to answer to you: title*, first name*, last name*, email address*, subject* Data that you spontaneously communicate to us | Legitimate interests of the data controller entity to provide you with adequate assistance |
| L’Institut Servier 50, rue Carnot 92284 SURESNES Cedex, France | Management of grant/donation applications | Identification data of the person authorized to represent the foundation/association: full name*, role*, email address*, telephone number* Data that you spontaneously communicate to us | Legitimate interests of the data controller entity to check the identity of the person authorized to represent the foundation/association |
| L’Institut Servier 50, rue Carnot 92284 SURESNES Cedex, France | Management of requests for mobility and research grants | Identification data that we need to process your request: title*, last name*, first name*, email address*, postal address*, birth date*, nationality*, phone number*, specialty* Documents necessary to process the request: application letter*, CV& works*, research project*, RPPS number, recommendation letter*, acceptance letter*, estimated budget* | Necessary in order to take steps take steps at the request of the data subject prior to entering into a contract |
3. How long do we keep the personal data?
The data controller will only keep the personal data for as long as necessary to achieve the purposes pursued in this Policy. More specifically:
| Purpose pursued | Data Retention |
|---|---|
| Management of requests relating to another subject | For all non-specific requests for information (i.e. not linked to a regulatory obligation) for which the law does not impose a specific period, we keep your personal data for 13 months starting from the day we received your request. |
| Management of grant/ donation applications | We keep your personal data for the duration of the request processing, and then for the statute of limitations. |
| Management of requests for mobility and research grants | We keep your personal data for the duration of the contractual relationship, then for the statute of limitations. |
4. How do we secure the personal data?
We put in place adequate technical and organisational measures to ensure security, integrity and confidentiality of the personal data.
These measures are designed with the aim of protecting personal data against unauthorised access, loss, destruction or alteration. In implementing these measures, we take into account the technologies available, the costs of implementation, as well as the nature, context and purposes of the processing of personal data and the risks to the rights and freedoms of the persons concerned.
5. Do we share the personal data?
The personal data processed by the entities of the Servier Group will only be accessible to duly authorized employees of the Servier entities concerned, as part of their work and on a need-to-know basis.
The personal data may also be transmitted to partners with whom the entities of the Servier Group collaborate in order to provide the expected services.
Finally, the entities of the Servier Group may communicate upon request the personal data to the competent authorities.
6. Do we transfer the personal data internationally?
Personal data may be transferred for the purposes described above to recipients located in a country that does not offer an adequate level of protection. In such a case, the Servier Group will take all necessary measures and guarantees to ensure the security of such transfers (such as the conclusion of European Commission Standard Contractual Clauses).
7. What are your rights?
According to the legal basis for the processing concerned and when the applicable law provides it, you have different rights:
- Request access to your personal data
- Update, correct or erase your personal data
- Request that some of the personal data you have gave to us be provided to you, or to another data controller, in a commonly used and machine-readable format (right to portability of your personal data)
- Define post-mortem directives
- Restrict or object to the processing of your personal data
- Withdraw your consent
You can exercise these rights with the Data protection Officer (“DPO”):
- By email to the following address: dataprivacy@servier.com
- By postal address to the following address:
The Data Protection Officer
SERVIER MONDE
50 rue Carnot
92284 Suresnes Cedex
You also have the right to lodge a complaint with the French personal data protection authority (CNIL), in particular on its website https://www.cnil.fr/fr/plaintes