Reporting violations 
of law or prohibited actions

Thank you for reporting the violation you have observed. The form below collects all the information necessary to process your report. Please provide as detailed and accurate information as possible, so that we can carefully analyse the described incident.
Compliance Officer

Zakłady Farmaceutyczne Polpharma S.A.

ul. Bobrowiecka 6, 00-728 Warsaw
When reporting a violation by means other than in writing, the Reporting Person will be asked to provide information corresponding to the information contained in the report.
Please submit your report by clicking SEND at the end.
or
Add information about the incident
Description of the incident, including the place, time and circumstances of the violation

In accordance with the Procedure for reporting breaches of law or prohibited activities, we accept 2 types of reports:

  1. Reports of breaches of law, i.e. an action or omission that is unlawful or intended to circumvent the law, falling within the catalogue set out in the Whistleblower Protection Act — e.g. corruption, product safety and compliance, transport safety, environmental protection, public health or consumer protection.
  2. Reports of prohibited activities, i.e. violations in areas other than those above — e.g. internal procedures, unethical conduct, as well as cases of mobbing, harassment and discrimination.
from
to
Submit Evidence
Skip this step
Evidence supporting the report

If you have evidence supporting your report, attach it here (you may attach more than one file). Each file may not exceed 2 MB.

Submit Evidence
Witnesses to the incident
Submit report

In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation; hereinafter: "GDPR"), we inform you that:

[Controller and Data Protection Officer, contact details]

  1. The controller of your personal data is the Polpharma Group company to which the report of a suspected breach of law, the Code of Ethics or the principles of the Polpharma Group Global Compliance Policy relates, i.e.:
    • 1.1. Zakłady Farmaceutyczne „Polpharma" S.A. with its registered office in Starogard Gdański (83-200), ul. Pelplińska 19, entered in the register of entrepreneurs of the National Court Register (KRS) under number 0000127044, by the District Court Gdańsk-Północ in Gdańsk, 7th Commercial Division of the KRS, NIP 5920202822, REGON 190929369, share capital: PLN 100,207,830, paid up in full; (each individually referred to as the "Controller").
  2. The Controller can be contacted in writing – at the address indicated in points 1 (above) and 2 (below).
  3. The Controller has appointed a Data Protection Officer, whom you may contact on all matters relating to the protection of personal data by writing to: Data Protection Officer, Zakłady Farmaceutyczne POLPHARMA S.A. (contact details) ul. Bobrowiecka 6, 00-728 Warszawa, or by e-mail at iod@polpharma.com, or by phone at +48 22 364 63 11.

[Purpose and legal basis for processing personal data]
4. Your personal data will be processed for the purposes of:

  • 4.1 fulfilling the Controller's legal obligations consisting in collecting Reports in order to prevent the commission of an offence and to respond to unlawful actions – pursuant to Art. 6(1)(c) GDPR in conjunction with Art. 304 §1 of the Act of 6 June 1997 – Code of Criminal Procedure, Art. 201 §1 and Art. 368 §1 of the Act of 15 September 2000 – Code of Commercial Companies, and Art. 3 of the Act of 28 October 2002 on the liability of collective entities for acts prohibited under penalty;
  • 4.2 communicating with you in connection with your message sent via the contact form – pursuant to Art. 6(1)(f) GDPR, i.e. on the basis of the legitimate interest pursued by the Controller, which is communication with the person who initiated contact with the Controller;
  • 4.3 possibly establishing, pursuing or defending claims between you and the Controller – pursuant to Art. 6(1)(f) GDPR, i.e. on the basis of the legitimate interest pursued by the Controller, which is the ability to pursue claims.
  1. No decisions will be made in relation to you in an automated manner, including profiling.
  2. Providing your personal data is voluntary, however it is necessary to establish contact with the Controller (failure to provide the data results in the Controller being unable to respond).

[Categories of recipients of personal data]
7. Your personal data may be disclosed to the following entities: entities of the Polpharma Group, including Zakłady Farmaceutyczne Polpharma S.A. with its registered office in Starogard Gdański, in order to respond to enquiries submitted via the form; IT service providers; entities providing advisory and legal services.
8. Your personal data may be made available to an advocate or legal counsel who, on the basis of an agreement with a Polpharma Group entity, is authorised to process such data and provides a guarantee of lawful processing of personal data and is bound by statutory confidentiality.
9. Your personal data may be made available to entities and authorities empowered to process such data on the basis of legal provisions.
10. The Controller does not intend to transfer your personal data to countries outside the European Economic Area or to an international organisation.

[Personal data retention period]
11. Personal data processed on the basis of Art. 6(1)(c) and (f) GDPR will be processed until the conclusion of the verification proceedings, and where an act contrary to law, the provisions of the Code of Ethics or the principles of the Polpharma Group Global Compliance Policy is found – until the limitation period for employee or contractual liability, or until the conclusion of criminal proceedings or other administrative or court proceedings related to such liability.
12. After the above period, personal data will be stored until any potential claims become time-barred.

[Rights]
13. You have: the right of access to the data concerning you, the right to rectify, erase or restrict its processing, the right to object to the processing of the data, and the right to data portability.
14. In order to exercise the rights listed above, you should contact the Controller or the Data Protection Officer (contact details indicated above).
15. Furthermore, you have the right to lodge a complaint with the supervisory authority for personal data protection (the President of the Personal Data Protection Office) if you believe that the processing of your data infringes the GDPR.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.