Roche Privacy Policy

Roche Thailand Limited ("Roche"), a legal entity duly registered under the laws of Thailand with Company Registration No. 0105514000345, is committed to protecting your privacy and will handle your Personal Data (as defined hereinbelow) in accordance with the Personal Data Protection Act B.E. 2562 (A.D. 2019) (“PDPA”), as amended from time to time, and any other applicable personal data laws and regulations issued by virtue thereof (“Data Protection Laws”). This Roche Privacy Policy (“Privacy Policy”) is applicable to any and all persons accessing and using our website at www.roche.co.th (“Website”), contacting us via email, or telephone call. This Privacy Policy may be amended from time to time in compliance with the Data Protection Laws which is in force at that time. Any changes to this Privacy Policy will become effective upon posting the revised Privacy Policy on the Website. Please read and review this Privacy Policy carefully to learn more about how we collect, use, transfer, share, disclose, and/or otherwise process your Personal Data, as well as to protect your Personal Data. In this Privacy Policy, the “Personal Data” shall be defined as any data pertaining to a person, which enables the identification of such person, whether directly or indirectly, but not including the data of the deceased specifically; and “Sensitive Personal Data” shall be defined as Personal Data, currently mentioned in Section 26 of the PDPA, which subject to enhanced requirements due to its sensitivity which includes Personal Data pertaining to ethnicity, race, political opinions, doctrinal, religious or philosophical beliefs, sexual behavior, criminal records, health records, disability, labour union, genetic data, biometric data or any other data which may affect you in the same manner, as prescribed by the supervisory authority.

Table of Contents
Personal Data Collected
Use and Disclosure of Personal Data
Direct Marketing
Cross-border Transfer of Personal Data
Your Choices
Security
Links to Other Sites
Rights to Your Personal Data
Contact Us

Personal Data Collected

1. How will Roche collect your Personal Data

Roche is concerned to protect your privacy. Generally, Roche will collect your Personal Data directly from you when you contacting us via the Website, email or telephone call.

Roche will only collect your Personal Data that is necessary for Roche to track and manage our interaction with you, for purposes set out in this Privacy Policy and for other legitimate purposes to carry out Roche’s business operations. The Personal Data to be collected may include:

  • your name, surname, contact details and other types of Personal Data collected when you register with Roche; 
  • an Internet Protocol Address (“IP Address”); 
  • any messages or comments you submit to us through email; 
  • any Personal Data you provide to Roche during your interaction with Roche such as name, surname, and contact details; and 
  • where you contact Roche regarding our products or services, including, without limitation, adverse drug reaction, Roche may need to collect your health-related data which is regarded as Sensitive Personal Data under the Data Protection Law

    2. Automatically Collected Personal Data

Roche may automatically receive certain types of information whenever you interact with us on the Website and through e-mails we may send to each other. Automatic technologies we use may include, for example, Web server Logs/IP addresses, cookies and Web beacons.

  • Web Server Logs/lP Addresses: An IP address is a number assigned to your computer whenever you access the internet. All computer identification on the internet is conducted with IP addresses, which allow computers and servers to recognize and communicate with each other. Roche collects IP addresses to conduct system administration and report aggregate information to affiliates, business partners and/or vendors to conduct site analysis and Website performance review. 
  • Cookies: A cookie is a piece of information that is placed on your computer or device when you access certain websites, including the Website. The cookie uniquely identifies your browser to the server. Cookies allow us to track, record and store your information on the server to help make the web experience better for you and to conduct site analysis and Website performance review. Cookies also enable Roche to recognise our Website users and their activities conducted on the Website. Most web browsers are set up to accept cookies, although you can reset your browser to refuse all cookies or to indicate when a cookie is being sent. Note, however, that some or all portions of our Website may not work properly if you refuse cookies. 
  • Web Beacons: On certain web pages or e-mails, Roche may utilize a common internet technology called a "Web beacon (also known as an "action tag" or "clear GIF technology"). Web beacons help analyze the effectiveness of Website by measuring, for example, the number of visitors to a site or how many visitors clicked on key elements of a site. 

Web beacons, cookies and other tracking technologies do not automatically obtain personally identifiable information about you. Only if you voluntarily submit personally identifiable information, such as by registering or sending e-mails, can these automatic tracking technologies be used to provide further Personal Data about your use of the Website and/or interactive e-mails to improve their usefulness to you. Roche will store Personal Data collected about you securely and access will only be allowed to those authorised and then only for the purpose for which it was collected and, where applicable, for which you have provided consent.

Roche will retain your Personal Data for as long as it is necessary and relevant for the business operations of Roche, and may delete from our records Personal Data no longer required or in use for the purposes identified in this Privacy Policy, other than Personal Data which we are required to retain under the Data Protection Laws or any other applicable laws or regulations. If possible and/or if required to do so under the Data Protection Laws, your Personal Data may be retained in a way that you cannot be identified (de-identification).
 

Your Choices

You have several choices when providing your Personal Data to Roche. You may decide not to provide your Personal Data at all by electing not to enter it into any forms or data fields on our Website or other forms (such as consent or meeting registration forms) which may be provided to you from time to time. If you choose not to provide your Personal Data, or provide incomplete or misleading information, Roche may not be able to provide you with information and/or access to services that may be of use or interest to you.

Certain websites may ask for your permission for certain uses of your Personal Data and you can elect to accept or decline those uses.

If you subscribe to particular services or communications, such as an e-newsletter, you will be able to unsubscribe at any time by following the instructions included in each communication. If you decide to unsubscribe from a service or communication or to update or remove your Personal Data, we will address your request and amend our records accordingly. We may require some additional information from you before we can process your request.

As described above, if you wish to prevent cookies from tracking you anonymously as you navigate our sites, you can reset your browser to refuse all cookies or to indicate when a cookie is being sent. Note, however, that some portions of our sites may not work properly if you refuse cookies.
 

Use and Disclosure of Personal Data

The purposes for which your Personal Data may be collected, held, used, processed, transferred, shared and disclosed include, but not limited to:

i. to contact you (or provide information and/or materials to you): 

  • with respect to your inquiries or concerns about Roche products and/or services. Please note that if you do not provide your Personal Data to Roche, we may not be able to respond to your inquiries or concerns, or to contact you back as requested; 
  • with respect to Roche products and/or services; 
  • to administer and conduct consulting and service arrangements with Roche; 
  • to administer or conduct educational and /or commercial meetings or programs; 
  • to send you both marketing and non-marketing materials which relating to Roche’s services and products; 
  • to update you on medical congress, events and news; and 
  • to conduct relevant market research; 

ii. Roche may use your Personal Data where required for the ordinary operation of our business (for example, to send you information about our products and services. If you do not wish to receive such information from Roche, you may opt-out by using opt out or unsubscribe link provided in each of our marketing email, or contact our Privacy Officer using contact details below);

iii. to fulfil obligations under relevant industry codes of conduct, meet regulatory requirements and legal obligations, including, without limitation, to report the adverse drug reaction to the competent regulatory. Please note that if you do not provide Roche with your Personal Data under this circumstance, Roche and you may not be able to comply with legal obligations under the applicable laws;

iv. to maintain your contact details, inquiries and responses in our records;

v. to monitor the safety and efficacy of our products; vi. to undertake survey, data analysis, and research;

vii. to develop our Website in order to provide you with adequate service and experience; and

viii. to fulfil your requests.

Roche will not disclose Personal Data about you to any other person except in accordance with this Privacy Policy or the Data Protection Laws, and only where necessary for the purposes described herein. Roche may disclose your Personal Data to the following persons and/or entities under circumstances stated below:

  • any persons or entities who/which Roche notified you prior to or at the time of supply of the Personal Data to Roche, or it is expressly permitted under any written agreement between you and Roche; 
  • to our service providers or vendors where it is necessary to provide you with a service or products which you have requested, or where it is necessary for support services to be provided in relation to our business activities (please note that such disclosures will only be to people and entities required to meet the same standards of data protection and which are prevented from using the information for their own marketing purposes or for any other unauthorised or unlawful purposes); 
  • to competent authorities, where the law requires, or in response to any demand by law enforcement authorities, or court order;  to the relevant regulatory authorities, where Roche is required to provide your Personal Data under the Data Protection Laws or any other applicable laws or regulations; 
  • to third parties that we use in the ordinary operation of our business, such as for conference organising, marketing, data processing and associated printing and mailing. For example, it may also be provided to Clinical Research Organisations for the purposes of medical research. We will only provide your Personal Information to reputable third parties and then only on a confidential basis where we are satisfied that those third parties will similarly and strictly comply with the Applicable Laws. These activities may involve the export of your Personal Data overseas as described above;
  • to any affiliate within the global Roche Group located within and outside of Thailand (“Roche Affiliates”), for the same kinds of purposes as listed above. Roche will implement appropriate measures to ensure that subsequent use and disclosure by the related company will be in compliance with the Data Protection Laws; 
  • to another company for the purpose of ensuring continuity of product supply and/or service if the supply of the product or service has been transferred to that company; and 
  • such third parties otherwise permitted or required by law.
     

Direct Marketing

At any time you may opt out of receiving any communications from Roche (other than as required for the operation of our business, e.g. regarding account payment if you have one with us by optout by using opt out or unsubscribe link provided in each of our marketing email, or contact our Privacy Officer using contact details below, although Roche may then be unable to provide you with all of the information regarding our programs, events, services or products which may be of benefit to you.
 

Cross-border Transfer of Personal Data

Your Personal Data may be transferred to, stored and processed by Roche’s affiliates worldwide, or Roche’s subcontractors or agents maintaining facilities or providing services. Roche will ensure that if your Personal Data is transferred outside of Thailand, it will still be treated in accordance with this Privacy Policy and that any other persons associated with your Personal Data will handle your Personal Data in compliance with Data Protection Laws. The countries in which your Personal Data may be transferred to include Australia, the United States and countries within the European Union and APAC.

Your Personal Data may be aggregated with data from other Roche sources and stored or processed on computers or web-based database systems located outside Thailand where data protection laws may differ from ours. In addition, your Personal Data may be stored, maintained and processed on computers or web-based database systems at Roche which may be accessed by and shared with Roche Affiliates, third-parties working with Roche Affiliates and/or regulatory authorities or as required by law. 

Roche will ensure to implement measures to require these third parties working with Roche and Roche Affiliates to strictly comply with the Data Protection Laws and the terms of this Privacy Policy.
 

Security

Roche uses technology and security precautions, rules and other procedures to protect your Personal Data from loss, unlawful or unauthorised access, use, disclosure, alteration, modification, interference or destruction. To ensure the confidentiality of your Personal Data is maintained, Roche also uses industry standard firewalls and password protection, including, where possible, one-time password or OTP. It is, however, your personal responsibility to ensure that the computer or device you are using is adequately secured and protected against malicious software, such as trojans, computer viruses and worm programs. Without adequate security measures (e.g. secure web browser configuration, up-to-date antivirus software, personal firewall software, no usage of software from dubious sources), there is a risk that the data and passwords you use to protect access to your data, could be disclosed to unauthorised third parties and Roche shall not be held responsible nor liable for any damage thereof. 
 

Links to Other Sites

Our Website may contain links to a number of other external websites that may offer useful information to you (“Third Party Websites”). This Privacy Policy does not apply to those sites, and we recommend communicating with them directly for information on their privacy policies. In no event shall Roche be held responsible or liable for any loss or damage incurred from your use of Third Party Websites.
 

Rights to Your Personal Data

Subject to the effectiveness of the Data Protection Laws, you may be entitled to various rights to your Personal Data under the Data Protection Laws which are as follows:

  1. Right of Access: To request to have access to or obtain copy of your Personal Data held by Roche, as well as to request the disclosure of the source of Personal Data which you did not consent to; 
  2. Right to Data Portability: In the event that Roche holds your Personal Data in a machinereadable format, you may request to obtain or to have your Personal Data in the said format transmitted to another data controller; 
  3. Right to Object: To object to our collection, use or disclosure of your Personal Data, particularly where the purpose of such collection, use or disclosure is for the direct marketing; 
  4. Right to Erasure: To request that your Personal Data held by Roche be deleted, destructed or de-identified; 
  5. Right to Suspension: To request that our collection, use or disclosure of your Personal Data be suspended; 
  6. Right to Rectification: If you believe that Personal Data Roche holds about you is incorrect, incomplete or inaccurate, you have the right to request us to amend or update it. Please note that Roche will consider if the information requires amendment and may request documentary proof prior to proceeding with said request; 
  7. Right to Withdraw Consent: Where your Personal Data is collected, used or disclosed based on consent as a legal basis, you may request to withdraw your consent at any time; and 
  8. Right to Lodge Complaint: To lodge complaint to the supervisory authority should you perceive that Roche violates or fails to comply with any provisions of the Data Protection Laws. Notwithstanding that, Roche would encourage you to first contact our Privacy Officer, using below contact details, before lodging any compliant to the supervisory authority. 

Request to exercise any of your rights to Personal Data stated above is subject to the conditions and limitations prescribed by the Data Protection Laws.

Your request should provide as much detail as possible to assist us to identify information relevant to you, such as your name and contact details, any former names and the information you believe Roche may hold about you. Where Roche holds information that you are entitled to access, we will endeavour to provide you with a suitable range of choices as to how you may access it (e.g. emailing or mailing it to you). In any event Roche will acknowledge receipt of your request within a reasonable period and in any event within 10 working days and endeavour to respond to your request within 30 days.
 

Contact Us

We are committed to constantly improving our procedures so that your Personal Data is treated appropriately.

If you have any questions about this Privacy Policy, or any complaint regarding treatment of your privacy by Roche, or would like to exercise any of your rights to Personal Data, please contact Roche’s Data Privacy Officer by one of the following means:

Roche Thailand Limited

By mail to:

Roche Thailand Limited
AIA Capital Center
89, 26th – 27th Floor,
Ratchadapisek Road,
Kwaeng Dindaeng,
Khet Dindaeng, Bangkok
10400 THAILAND

Attn: Privacy Officer

By email
to: chomphunut.thaw[email protected]

 

Dated: 12 Nov 2020