Novartis Healthcare Phils. Inc., having its registered office at 5F Ayala North Exchange Tower 1 Ayala Ave, corner Amorsolo and Salcedo Streets, Brgy. San Lorenzo, Makati City, is responsible for the processing of your personal information as it decides why and how it is processed, thereby acting as the “data controller.” It may exercise this responsibility alone or jointly with other company(-ies) in the Novartis group, acting as “co-controller(s).” In this Privacy Notice, “we” or “us” refers to Novartis Healthcare Phils. Inc. and its group companies.
For the purpose of this data privacy notice (“Notice”), it applies to the users (hereafter referred to as “you”) of our websites, web applications, or mobile applications (collectively referred to as “app”) where this Notice has been specifically referenced.
We invite you to carefully read this Notice, which sets out the context in which we are processing information that relates directly or indirectly to you as an individual (“personal information”) and explains your rights with respect to the processing of your personal information.
Though this Notice is intended for individuals interacting with the app mentioned, you may be asked to refer to additional privacy policies available on our corporate website or separate data privacy notices on our country-specific websites if you reside in a certain location or if the processing activities are governed by other policies or notices. Wherever required, we will also present you with specific privacy notices for activities not covered under this Notice, including but not limited to recruitment, employment, third-party management, or patient support.
Note that if you access any third-party link or website from our app, you may need to refer to the privacy policies of such third parties. Novartis does not endorse and is not responsible for the information or privacy practices of websites or services owned by third parties.
We consider privacy a very important matter. We are committed to ensuring that any personal information we receive is processed and protected in accordance with applicable data protection laws and Novartis policies and standards.
If you have any questions about the processing of your personal information or this Notice, please contact our data protection officer at ph.cdpo@novartis.com.
We may change or update this Notice from time to time by posting a new Notice on this app. Please check this Notice occasionally to stay aware of any changes.
Novartis Healthcare Phils. Inc. processes personal information about you when you visit our website to raise awareness among patients who have been prescribed Inclisiran (Sybrava™).
1. What personal information do we have about you?
The personal information may either be directly provided by you (e.g., when filling a web form or interacting with a website or app), provided by third parties owning or managing the apps, or obtained through trusted publicly available sources, having obtained your consent where necessary under applicable law. We may collect various types of personal information about you, including:
- Your electronic identification data (e.g., login, passwords, IP address, online identifiers/cookies, system activity logs).
- Information regarding your browser and device (e.g., internet service provider’s domain, browser type and version, operating system, screen resolution).
- Statistics in relation to your use of our website and app (e.g., pages visited, time spent).
- Usage data (e.g., date and time of access, files downloaded).
- Your device’s location when using our app (unless disabled by your device settings).
- Any other information you provide when using our website and app.
Please note that we will not knowingly collect, use, or disclose personal data from a minor under the age of [13] without obtaining prior consent from a parent or legal guardian.
In some countries, information relating to a company (“legal person”) is also considered personal information. If the information collected is specific to a legal entity, we will treat it as personal information in accordance with applicable data protection law.
2. For which purposes do we use your personal information and why is this justified?
We will not process your personal information without a proper legal justification. We will only process your personal information if:
- We have obtained your prior consent;
- The processing is necessary to perform our contractual obligations or to take pre-contractual steps;
- The processing is necessary to comply with our legal or regulatory obligations;
- The processing is necessary for our legitimate interests without unduly affecting your rights.
Please note that when processing your personal information on the basis of legitimate interests, we always seek to maintain a balance between our interests and your privacy. Examples of such legitimate interests include:
- Developing a trustful professional relationship;
- Promoting Novartis innovation in the pharmaceutical field;
- Managing Novartis human and financial resources;
- Preventing fraud or criminal activity;
- Meeting corporate and social responsibility objectives.
If you have consented to the processing of your personal information, you have the right to withdraw that consent at any time. For more information, please contact us as indicated in section 7 below.
2.2 Purposes of the processing
We process your personal information for specific purposes, including:
- Managing and improving our website and apps;
- Measuring the usage of our website and apps;
- Personalizing your experience;
- Improving product quality and expanding business activities;
- Monitoring and preventing fraud;
- Managing IT resources;
- Ensuring compliance with legal requirements.
The collected data may also be used for standard purposes, including:
- Organizing tender offers;
- Communicating during contract terms;
- Managing mergers and acquisitions;
- Archiving and record-keeping.
3. Who has access to your personal information and to whom is it transferred?
We will not sell, share, or otherwise transfer your personal information to third parties other than those indicated in this Notice. Your personal information can be accessed by the following categories of recipients on a need-to-know basis:
- Our personnel;
- Independent agents or brokers;
- Other suppliers and service providers;
- IT systems providers and consultants;
- National and/or international regulatory bodies.
The above parties are contractually obliged to protect the confidentiality and security of your personal information. If we transfer your personal information to external parties in other jurisdictions, we will ensure compliance with applicable data protection laws.
4. How do we use cookies and other similar technologies on our websites and apps?
We may collect and process information about your visit to this website or app, such as pages you visit and searches you perform. We may use this information to help improve our services. Cookies are created and stored on the user's device when the browser loads a website. They help a website remember your preferences and settings.
You can set your browser to notify you when you receive a cookie, enabling you to decide whether to accept it. When you visit our websites, you may see a cookie-setting banner allowing you to manage your cookie preferences.
5. How do we protect your personal information?
We have implemented appropriate technical and organizational measures to provide an adequate level of security and confidentiality for your personal information, protecting it against accidental or unlawful destruction, loss, unauthorized access, and other unlawful forms of processing.
6. How long do we store your personal information?
We will retain your personal information only as long as necessary to fulfill its purpose or comply with legal requirements. Personal data will be stored until July 31, 2024, unless a longer retention period is required by law.
7. What are your rights and how can you exercise them?
You may exercise the following rights:
- The right to be informed about what personal information we have about you;
- The right to access and request corrections of your personal information;
- The right to request the erasure of your personal information;
- The right to withdraw consent at any time;
- The right to object to processing for direct marketing;
- The right to request portability of your personal information;
- The right to object to automated decision-making.
If you have a question or wish to exercise your rights, please email our data protection officer at ph.cdpo@novartis.com.
8. How will you be informed of the changes to our Privacy Notice?
We may change or update this Notice by posting a new privacy notice. Please check this Notice occasionally for changes.
Last updated: November 7, 2023