Privacy Statement for Healthcare Professionals
Roche Thailand Limited (“Roche”), a legal entity duly registered under the laws of Thailand with Company Registration No. 0105514000345, is committed to protecting your privacy and will handle your Personal Data (as defined hereinbelow) in accordance with the Personal Data Protection Act B.E. 2562 (A.D. 2019) (“PDPA”), as amended from time to time, and any other applicable personal data laws and regulations issued by virtue thereof (“Data Protection Laws”).
This Privacy Statement for Healthcare Professionals (“Privacy Statement”) is applicable to any and all persons who are or have been practicing in the healthcare industry, including, without limitation, doctor, nurse and pharmacist (collectively referred to as “HCPs”).
Please read and review this Privacy Statement carefully to learn more about how we collect, use, transfer, share, disclose, and/or otherwise process your Personal Data, as well as to protect your Personal Data.
Cross-border Transfer of Personal Data
Retention of Your Personal Data
Rights to Your Personal Data
Personal Data Collected
1. How will Roche collect your Personal Data?
1.1 Generally, Roche collects Personal Data directly from you when interacting with you either in person, or when you interact with us via emails, instant messaging applications, telephone calls, or through our at website at https://www.roche.co.th (“Website”) or RocheConnect which is Roche’s online platform specifically provided to HCPs by Roche (“RocheConnect”), or any other similar means of communication.
1.2 Roche may also collect your Personal Data from sources other than directly from you, including, without limitation, from public sources, both online and offline.
1.3 In certain circumstances, Roche may automatically receive certain types of information whenever you interact with us on the Website and through emails we may send to each other, or when you accessing or using our Website or RocheConnect, including web server Logs/Internet Protocol addresses (“IP”), cookies and web beacons.
2. What types of Personal Data collected by Roche?
2.1 Roche collects various types of your Personal Data including your full name, title, secondary title, date of birth, age, gender, nationality, contact address, mobile phone number, LINE ID or other data relating to the instant messages applications on mobile or computer, personal email address, work email address, office phone number, office address, workplace, profession, specialty, professional license number and picture (photo).
2.2 If you access Website or RocheConnect, or when you contact or interact with Roche on our sites and in some e-mails we may send each other, Roche may automatically receive certain types of information which may include your Personal Data, such as web server logs/IP addresses, cookies, Web beacons and third party application and content tools.
2.2.1 Web Server Logs/IP Addresses. An IP address is a number assigned to your computer whenever you access the Internet. All computer identification on the Internet is conducted with IP addresses, which allow computers and servers to recognize and communicate with each other. Roche collects IP addresses to conduct system administration and report aggregate information to affiliates, business partners and/or vendors to conduct site analysis and website performance review.
2.2.3 Web Beacons. On certain webpages on our Website and/or RocheConnect or e-mails, Roche may utilize a common Internet technology called a “Web beacon” (also known as an “action tag” or “clear GIF technology”). Web beacons help analyze the effectiveness of websites by measuring, for example, the number of visitors to a site or how many visitors clicked on key elements of a site. Web beacons, cookies and other tracking technologies do not automatically obtain your Personal Data. Only if you voluntarily submit your Personal Data, such as by registering or sending e-mails, can these automatic tracking technologies be used to provide further information about your use of the Website or RocheConnect, and/or interactive e-mails to improve their usefulness to you.
2.3 In addition to Clause 1.2 above, if you register as a user of RocheConnect Roche may further collect your password for accessing RocheConnect.
2.4 If you are engaged by Roche as a third party service provider – for example, speaker in the medical congress, events, meeting, sponsored programs, events and initiatives, workshops and seminars, Roche may further collect your educational background, academic background, work experiences, bank account details, identification card number and any other data containing on the Thai national identification card, Personal Data containing in the passport (including passport number, place of birth, gender, and height), and photo, video and/or audio recording of you during the medical congress, events, meeting, sponsored programs, events and initiatives, workshops and seminars.
2.5 In case of clinical trial researches or any academic activities, Roche may collect your resume containing your Personal Data and/or Sensitive Personal Data.
2.6 Roche may collect any other types of Personal Data which you may provide to Roche via online sources and communications from time to time, including, without limitation, through websites, email, SMS, instant messaging applications, and other online tools.
2.7 Roche may also collect data pertaining to your religion and/or blood type which are categorized as sensitive personal data under the PDPA (“Sensitive Personal Data”) when collecting a copy of your Thai identification card.
In relation to the use of our Website or RocheConnect, you could decide not to submit any Personal Data at all by not entering it into any forms or data fields on our Website or RocheConnect, and not using any available personalized services.
If you choose to submit Personal Data, you have the right to see and correct your data at any time by accessing the application or contact us using our contact details provided below. Certain sites may ask for your permission for certain uses of your information and you can agree to or decline those uses. You may opt-in to receive our services and communications, including, without limitation to, information about our products and services, sponsored programs, events and initiatives, customer feedback, and medical information, through various communication channels such as email, text messages (including instant messages (such as via LINE Application or other instant messaging applications) and SMS), calls and direct mail. We may also send such information to you via communication channels which you have initiated in contacting us such as via instant messaging application. You will be able to unsubscribe at any time by following the instructions included in each communication, or contact us. If you decide to unsubscribe from a service or communication, we will work to remove your information promptly, although we may require additional information before we can process your request.
As described above, if you wish to prevent cookies from tracking you anonymously as you navigate our sites, you can reset your browser to refuse all cookies or to indicate when a cookie is being sent.
You can visit our Website and RocheConnect without providing any personal data. However, without providing such personal data, you may not be able to utilize certain functions on our Websites or RocheConnect, or acquire our services, either in part or in whole.
There are certain circumstances which you may provide Personal Data, including Sensitive Personal Data, of other persons to Roche, whether via instant messaging applications, telephone calls, emails, Website, RocheConnect or any other means; for example:
i. when you choose to send a link or a message to a friend or colleague referring them to a Roche’s Website or RocheConnect. In such case, the email addresses you may provide for a friend will be used to send your friend information on your behalf and will not be collected or used by Roche or other third parties for additional purposes.
ii. when you disclose Personal Data and/or Sensitive Personal Data of your patients to us for medical treatment and research purposes.
In such circumstances, you shall represent and warrant that you have duly obtained consent or explicit consent, as the case may be, from such other persons, or that there is any other legal basis for you to disclose their Personal Data to Roche.
Use and Disclosure of Personal Data
The purposes for which your Personal Data may be collected, held, used, processed, transferred, shared and disclosed include, but not limited to:
i. to enable you to register as a user on and have access to RocheConnect.
ii. to contact you (or provide information and/or materials to you):
- with respect to your inquiries or concerns about Roche products and/or services. Please note that if you do not provide your Personal Data to Roche, we may not be able to respond to your inquiries or concerns, or to contact you back as requested;
- with respect to Roche products and/or services;
- to administer and conduct consulting and service arrangements with Roche;
- to administer or conduct educational and /or commercial meetings or programs;
- to send you both marketing and non-marketing materials which relating to Roche’s services and products, including any materials, news and updates on medical information and any other matters relating to the healthcare professional industry;
- to update you on and invite you to medical congress, events, meeting, sponsored programs, events and initiatives, workshops and seminars; and
- to conduct relevant market research;
ii. to perform contractual obligations, or to proceed with your request to enter into any contractual relationship with us. Please note that if you do not provide Roche with your Personal Data under this circumstance, Roche may not be able to perform contractual obligations, or proceed with your request to enter into a contractual relationship with us;
iii. to arrange for courier where Roche or Roche’s authorized agents/representatives need to collect materials and/or documents from you;
iii. Roche may use your Personal Data where required for the ordinary operation of our business (for example, to send you information about our products and services. If you do not wish to receive such information from Roche, you may opt-out by using opt out or unsubscribe link provided in each of our marketing email, or contact our Privacy Officer using contact details below);
iv. to fulfil obligations under relevant industry codes of conduct, meet regulatory requirements and legal obligations, including, without limitation, to report the adverse drug reaction to the competent regulatory. Please note that if you do not provide Roche with your Personal Data under this circumstance, Roche and you may not be able to comply with legal obligations under the applicable laws;
v. to arrange for and provide assistance in relation to visa application, tickets and accommodation bookings where you are engaged by Roche as a service provider, or where you are invited by Roche to attend medical congress, events, meeting, sponsored programs, events and initiatives, workshops and seminars;
vi. to arrange and make payments to you where applicable, including to prepare and issue any tax related documents for such payments, and to perform any of our tax obligations;
vii. to collaborate, liaise, support or engage in any clinical trial researches and academic activities;
viii. to maintain your contact details in our system, and, if any, your inquiries and responses in our records;
ix. to monitor the safety and efficacy of our products;
x. to undertake survey, data analysis, and research. The information will be helpful for us to better understand your needs and how we can improve our products and services. It helps us also to personalize certain communications with you about services and promotions that you might find interesting. For example, we may analyze the gender or age of visitors to sites about a particular medication or disease state, and we may use that analysis of aggregate data internally or share it with others;x. to develop our Website and RocheConnect in order to provide you with adequate service and experience; and
xi. to fulfil your requests.
i. any persons or entities who/which Roche notified you prior to or at the time of supply of the Personal Data to Roche, or it is expressly permitted under any written agreement between you and Roche;
ii. to our service providers or vendors where it is necessary to provide you with a service or products which you have requested, or to arrange for the courier and/or collection of any materials or documents from you, or where it is necessary for support services to be provided in relation to our business activities (please note that such disclosures will only be to people and entities required to meet the same standards of data protection and which are prevented from using the information for their own marketing purposes or for any other unauthorised or unlawful purposes), including, without limitation to, any persons, companies or agents doing technological maintenance or working on our behalf to help fulfill business transactions, such as providing customer services, sending marketing communications about our products, services and offers, as well as vendors providing venues for medical congress, events, meeting, sponsored programs, events and initiatives, workshops and seminars, transportation services, tickets and accommodation bookings service, visa and immigration services, accounting firms, auditing firms and legal consultants;
iii. to public and media with regard to our collaborations. This will however be subject to our agreed terms under the relevant agreement;
iv. Roche’s subsidiaries and affiliates, both within and outside of Thailand;
v. to government authorities for the purposes described above, including, without limitation to, the Revenue Department, and any embassies for the purposes of arranging and applying for your visa;
vi. to respond to appropriate requests of legitimate government agencies or where required by applicable laws, court orders, or government regulations;
vii. in connection with the sale, assignment or other transfer of the business of the site to which the data relates; or
viii. where needed for corporate audits or to investigate or respond to a complaint or security threat.
No Third-Party Direct Marketing Use. Roche will not sell or otherwise transfer your Personal Data which you have provided to us to any third parties for their own direct marketing use unless we provide clear notice to you and obtain your consent for your Personal Data to be shared in this manner.
Cross-border Transfer of Personal Data
Roche uses technology and security precautions, rules and other procedures to protect your personal information from unauthorized access, improper use, disclosure, loss or destruction. To ensure the confidentiality of your information, Roche uses also industry standard firewalls and password protection. It is, however, your personal responsibility to ensure that the computer you are using is adequately secured and protected against malicious software, such as trojans, computer viruses and worm programs. You are aware of the fact that without adequate security measures (e.g. secure web browser configuration, up-to-date antivirus software, personal firewall software, no usage of software from dubious sources) there is a risk that the data and passwords you use to protect access to your data, could be disclosed to unauthorized third parties.
Links to Other Sites
Our Website and RocheConnect contain links to a number of external websites that may offer useful information to you (“Third Party Websites”). This Privacy Statement does not apply to those sites, and we recommend communicating to them directly for information on their privacy policies. In no event shall Roche be held responsible or liable for any loss or damage incurred from your use of Third Party Websites.Services: We may provide services based on third party applications and content tools on Website and/or RocheConnect, such as Google Maps or QUARTAL FLIFE. These third parties may automatically receive certain types of information, which may include your Personal Data, whenever you interact with us on our sites using such third party applications and tools.
Retention of Your Personal Data
Roche will store Personal Data collected about you securely and access will only be allowed to those authorised and then only for the purpose for which it was collected and, where applicable, for which you have provided consent. Roche will retain your Personal Data for as long as it is necessary and relevant for the business operations of Roche, and may delete from our records Personal Data no longer required or in use for the purposes identified in this Privacy Statement, other than Personal Data which we are required to retain under the Data Protection Laws or any other applicable laws or regulations. If possible and/or if required to do so under the Data Protection Laws, your Personal Data may be retained in a way that you cannot be identified (de-identification).
Rights to Personal Data
Subject to the effectiveness of the Data Protection Laws, you may be entitled to various rights to your Personal Data under the Data Protection Laws which are as follows:
- Right of Access: To request to have access to or obtain copy of your Personal Data held by Roche, as well as to request the disclosure of the source of Personal Data which you did not consent to;
- Right to Data Portability: In the event that Roche holds your Personal Data in a machine-readable format, you may request to obtain or to have your Personal Data in the said format transmitted to another data controller;
- Right to Object: To object to our collection, use or disclosure of your Personal Data, particularly where the purpose of such collection, use or disclosure is for the direct marketing;
- Right to Erasure: To request that your Personal Data held by Roche be deleted, destructed or de-identified;
- Right to Suspension: To request that our collection, use or disclosure of your Personal Data be suspended;
- Right to Rectification: If you believe that Personal Data Roche holds about you is incorrect, incomplete or inaccurate, you have the right to request us to amend or update it. Please note that Roche will consider if the information requires amendment and may request documentary proof prior to proceeding with said request;
- Right to Withdraw Consent: Where your Personal Data is collected, used or disclosed based on consent as a legal basis, you may request to withdraw your consent at any time; and
- Right to Lodge Complaint: To lodge complaint to the supervisory authority should you perceive that Roche violates or fails to comply with any provisions of the Data Protection Laws. Notwithstanding that, Roche would encourage you to first contact our Privacy Officer, using below contact details, before lodging any compliant to the supervisory authority.
Request to exercise any of your rights to Personal Data stated above is subject to the conditions and limitations prescribed by the Data Protection Laws.
Your request should provide as much detail as possible to assist us to identify information relevant to you, such as your name and contact details, any former names and the information you believe Roche may hold about you. Where Roche holds information that you are entitled to access, we will endeavour to provide you with a suitable range of choices as to how you may access it (e.g. emailing or mailing it to you). In any event Roche will acknowledge receipt of your request within a reasonable period.
Updates to Privacy Statement
From time to time, Roche may revise this Privacy Statement. Any such changes to this Privacy Statement will be promptly communicated on the Website, RocheConnect, or through any other channels as deemed appropriate.
How to Contact Roche
For questions regarding this Privacy Statement, or if you wish Roche to amend or delete your profile, or you would like to exercise any of your rights to Personal Data as stated above, please contact Roche at the following address:
Roche Thailand Ltd.
89 AIA Capital Center 26th Floor
Ratchadapisak Road, Kwaeng Dindaeng,
Khet Dindaeng, Bangkok 10400 Thailand
Or contact Roche’s Data Protection Officer at: [email protected]
Version 2.0, dated 10-Dec-2020