Privacy Policy
PRIVACY NOTICE FOR IUdoTM
Last updated: 24 June 2024
- INTRODUCTION
This Privacy Notice describes the practices of Pfizer S.A. de C.V. ("Pfizer" or "we") with respect to the personal data collected in connection with the Program (defined below), in relation to:
- Patients (defined below);
- Caregivers (defined below); and
- HCPs (defined below);
each (“you” or “your”).
It covers:
- personal data collected through IUdoTM (the "App"); and
- personal data otherwise collected and processed in connection with the Program, including but not limited to any personal data submitted offline to the third party appointed by Pfizer to administer the Program (“Program Manger”).
- If you are a user of the App: personal data collected to create your Pfizer Account Global Patient Authentication (“Pfizer Account GPA”).
- THE APP
The App is intended for use by Patients (“Patients”) (or their caregivers) (“Caregivers”) who: (i) are prescribed, by their healthcare provider (“HCP”), a Pfizer medication supported by a Pfizer Patient assistance program (the “Program”); (ii) have signed the Patient assistance program enrollment form (the “Form”) and shared the same with the Program Manager. The App enables Patients to complete the enrollment process into the Program and to assess their eligibility for participation.
Patients are not required to use the App and have the option to provide the information required to participate in the Program to the Program Manager without using the App, typically by way of email.
- PERSONAL DATA
"Personal Data" is data that identifies you as an individual or relates to an identifiable individual.
Patient and Caregiver Personal Data
You may be asked to provide, or we may otherwise collect from third parties such as insurers, Pharmacists and /or your HCP, the following Personal Data in connection with the Program:
- A copy of the Form and the Personal Data contained therein;
- Registration/Profile data including but not limited to: full name, date of birth, gender, address, contact number, email address and password;
- Caregiver name, relationship to Patient and contact number (if applicable);
- Communication and language preferences;
- Patient verification information: copies of national ID, passport and/or resident visa (for Patients who are not citizens of the country in which they are signing up to the Program);
- Patient health data:
- Form signed by the Patient (or caregiver, if applicable);
- Pfizer’s prescribed medicine prescription copy(ies) and details (including dosage information, prescription start and expiration date,);
- Financial data/proof of income required for eligibility assessment by Program Manager;
- Medical insurance documentation and details;
- Copies of Pfizer prescribed medicine purchase receipts;
- Evidence in relation to your use of the medication provided under the Program (e.g. Photographs taken by you and / or receipts); and
- Personal Data contained within any other documents which you or related parties are required to submit in connection with the Program.
For users of the App, you will be asked to provide the below Personal Data necessary to create your Pfizer Account GPA, which enables you to create one account that can be used to log in to select Pfizer apps/websites and services that feature Pfizer GPA icon and connected to your Pfizer account, including this App. In addition, we obtain information from third-party sources. If you create or log into your Pfizer Account GPA through a third-party platform (such as Google, Apple), we will have access to certain information from that platform, such as your name, birthday, or other information, in accordance with the authorization procedures determined by such platform.
- name, last name, email address, account password.
Whilst you are not required to provide us with any Personal Data, if you do not this will impact your ability to participate in the Program. We require the information we request for the Program Manager to administer the Program and to perform eligibility assessments in connection with the Program.
HCP Personal Data
We also collect the following information in relation to HCPs in the Form:
- Full name;
- Practice / Institution name;
- Specialty;
- Address;
- Phone;
- Email;
- Preferred communication language and channel;
- Report frequency preference; and
- Working hours.
- DATA STORAGE AND ENCRYPTION
Your Personal Data is stored on cloud based servers in the United States of America owned or controlled by Pfizer Inc. Note that your personal data will be stored on the cloud regardless of the method by which your personal data is provided to the Program Manager (i.e. Whether by way of email, via the App, or by another offline method.)
For Personal Data collected through your Pfizer Account GPA, such data is stored on cloud-based servers in Europe (with a primary data center in Frankfurt, Germany, and a failover in Dublin, Ireland) controlled by Pfizer Inc. The Personal Data stored on these servers is encrypted both in transit and at rest.
If you are a user of the App:
The Personal Data listed above that you share through the App will not be stored locally on your device.
- HOW WE USE PERSONAL DATA
The Program Manager will primarily be the party which accesses, uses and otherwise processes your Personal Data in connection with the administration of the Program. Pfizer will not access your Personal Data except under exceptional and limited circumstances and within a controlled environment. For example, Pfizer (and / or its third party IT service providers) may have visibility over your Personal Data in the course of servicing and managing the cloud on which your Personal Data is stored. Access to the area of the cloud on which your Personal Data is stored is limited by access control mechanisms so that only those staff members and contractors with specific privileges, and who need access to it to manage the system configuration, have such access. In all cases those individuals would be bound by appropriate contractual requirements with regards to strict confidentiality.
If you are a Patient, your Personal Data will be used to:
- enable you to participate in the Program;
- provide customer services to you in managing the lifecycle of your engagement in the Program;
- respond to your inquiries and fulfill your requests, such as to send you notifications and emails as reminders and updates;
- PIN/invitation code or password resets;
- send administrative information to you, such as information regarding the App (if you are an App user) and changes to our terms, conditions, and policies;
- enable the Program Manager to complete your eligibility assessment and to subsequently enroll you to the Program, if successful;
- operate our business to comply with our legal obligations and to provider the Program and (where applicable) the App, including (where appropriate on an aggregated level):
- to conduct data analysis to improve the user experience.
- (where you (Patient or Caregiver) are a user of the App) to identify usage trends in the use of our App and analyse the effectiveness of our communications;
- to detect, prevent, and investigate fraud, including (cyber) security monitoring and prevention;
- to enhance, improve, or modify our services;
- to better understand how our services impact you and those for whom you care;
- to track and respond to concerns, including engaging in regulatory monitoring and reporting obligations related to adverse events, product complaints, and Patient safety; and
- to operate and expand our business activities.
For your Pfizer Account GPA, we may use your Personal Data in the following ways:
- To create your Pfizer Account GPA; so you can access Pfizer websites/app including this App.
If you are a HCP your Personal Data will be used:
- to retain records verifying that you have approved the Patient’s participation in the Program;
- to retain records in connection with the prescriptions you prescribe to Patients; and
- to contact you in connection with a Patient’s participation in the Program.
- HOW WE DISCLOSE PERSONAL DATA
Your Personal Data may be disclosed (either by us or the Program Manager) as follows:
- (Patients only) To third parties in connection with the administration of the Program, such as your HCP;
- To our third-party service providers, to provide services such as information technology (including the management and development of the App) and related infrastructure provision (such as in connection with the data centre we use in the U.S.), customer service, email delivery, auditing and other services.
- We also use and disclose your Personal Data as we believe to be necessary or appropriate:
- To comply with applicable law and our regulatory monitoring and reporting obligations (which may include laws outside your country of residence), to respond to requests from public and government authorities (which may include authorities outside your country of residence), to cooperate with law enforcement, or for other legal reasons;
- To enforce our terms and conditions;
- To protect our rights, privacy, safety or property, and/or that of our affiliates, you or others.
In addition, we may use, disclose or transfer Personal Data to a third party in connection with any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings).
We may aggregate the Personal Data that our App users provide to us. Provided the aggregated data does not personally identify you or any other individual, we may use and disclose such aggregated data for any purpose.
- INDIVIDUAL RIGHTS. Rights of Access, Rectification, Cancellation and Opposition
You as Owner of your Personal Data have the right to: (i) know what personal data are processed by Pfizer and the purposes of its treatment (right to access); (ii) request the correction of your personal data in case they are outdated, inaccurate or incomplete (right of rectification); (iii) that your personal data is deleted from the records or databases of Pfizer when they consider that they are not being used properly (right of cancellation); and (iv) oppose the use of your personal data for specific purposes (right to object) (as a whole and hereinafter "the ARCO Rights"). You also have the right to revoke at any time the consent you have given us for the processing of your personal data to the extent permitted by law.
The request to exercise the ARCO Rights (or the formulation of any questions or complaints you may have) may be made by the Owner through the forms established by Pfizer or by contacting the Privacy Compliance Officer at the email DATAPROTECTMX@pfizer.com In any request you must indicate your name, provide a copy of your official identification (passport, professional card or official identification), describe clearly and precisely the personal data and / or sensitive personal data to which you wish to access, rectify, cancel or oppose and any other element that facilitates the location of your data, as well as any other requirement established by the Law and other applicable provisions. Please note that we may need to retain certain Personal Data for recordkeeping purposes and/or to complete any transactions that you began prior to requesting a change or deletion.
Your applications will be evaluated in the terms established in the applicable laws. Upon your request, our Privacy Compliance Officer will inform you: (i) the time frames within which you will receive an answer to your request; (ii) whether there are forms or means you can use to submit your application, and (iii) the manner or means in which we will deliver the information to you.
If you do request the deletion of your Personal Data this will prevent your continued participation in the Program. If you decide to delete your Pfizer Account GPA you will lose access to the App and any Pfizer websites/apps associated with your Pfizer Account GPA, and we will delete all your personally identifiable information that you have provided to create your Pfizer Account GPA from our records and data bases. If you decide, in the future to join another program using Pfizer Account GPA, you will need to create a new Pfizer Account GPA. Please note that we may need to retain certain Personal Data following a deletion request in accordance with the RETENTION PERIOD section below.
You may have a right to lodge a complaint with a data protection authority competent for your habitual residence, place of work, or place of alleged infringement. This Notice is governed by the Law, its Regulations and other applicable laws of Mexico, being the National Institute of Transparency, Access to Information and Protection of Personal Data (hereinafter the "INAI") the federal body in charge of safeguarding the rights to the protection of personal data (www.inai.org.mx).
If you are a user of the App:
Please note that uninstalling the App from your device does not trigger the deletion of your Personal Data and that to exercise your right to erasure you would need to contact us (or the Program Manager) as per the CONTACT US section below.
- DATA SECURITY
We have implemented organizational, technical and administrative measures to protect your Personal Data. Whilst we regularly monitor our systems for possible vulnerabilities and attacks, there is no guarantee that your information may not be accessed, disclosed, altered, or destroyed as a result of a malicious breach of our physical, technical, or managerial safeguards.
- RETENTION PERIOD
We will retain your Personal Data for as long as needed or permitted in light of the purpose(s) for which it was obtained and as outlined in this Privacy Notice. The criteria used to determine our retention periods include: (i) the length of time we have an ongoing relationship with you; (ii) whether there is a legal obligation to which we are subject; or (iii) whether retention is advisable in light of our legal position (such as in regard to the enforcement of the App Terms of Use (App users only), applicable statutes of limitations, litigation or regulatory investigations).
- CROSS-BORDER TRANSFER
The data we collect in connection with the Program, may be stored and processed in any country where we have facilities or in which we engage service providers, including in the United States (where our cloud servers are located) and where our affiliates operate.
- USE BY MINORS
The App is not directed to individuals under the age of sixteen (16), and we do not knowingly collect Personal Data from such individuals. If you are under the relevant age of consent in your jurisdiction, you will need your parent's or legal guardian's permission to use the App. Please consult with your parent or legal guardian before installing the App.
If you are providing us with Personal Data of individuals under the age of sixteen (16) in connection with the Program generally (for example, if you are a Caregiver), you represent that you have the appropriate authority to do so and that you can demonstrate such authority to Pfizer upon request.
- UPDATES
From time to time, we will update this Privacy Notice. Any changes will become effective when we post the revised Privacy Notice. This Privacy Notice was last updated as of the "Last Updated" date shown above.
- CONTACT US
The company responsible for collection, use, and disclosure of your Personal Data under this Privacy Notice is:
Pfizer S.A. de C.V.
If you have questions about this Privacy Notice, or if you would like to request to exercise any individual rights, please contact us at DATAPROTECTMX@pfizer.com or write to the following address:
Paseo de los Tamarindos No. 40, Colonia Bosques de las Lomas, Alcaldía Cuajimalpa, Mexico City, C.P. 05120, Mexico.
You may also contact our data protection officer responsible for your country or region, if applicable. To find their contact information, visit DPO.Pfizer.com.