HCP PRIVACY NOTICE
Last Updated: June 2023
HCP PRIVACY NOTICE
INTRODUCTION
This Privacy Notice for Health Care Professionals (“HCP Privacy Notice” or “Privacy Notice”) describes the Personal Data that the Pfizer company named in the “Contact Us” section below (hereinafter, “Pfizer”, “us” or “we”) may collect and further process about you as a healthcare professional (“HCP”) when we interact with you; how we use that data, i.e., for the fulfilment of which processing purpose/s we may use them; how we protect it; and the choices you may make with respect to your Personal Data.
If you are interacting with us online, please also see the privacy notice posted on the website or application that you are using.
PERSONAL DATA
“Personal Data” is data that identifies you as an individual or relates to an identifiable individual. We will collect Personal Data when, to the extent applicable, we meet with you, when you participate in our programs, activities, industry events, trade shows, or in connection with your inquiries and communications with us. To the extent permitted under applicable law, we also collect Personal Data from data companies providing information services in the healthcare sector, publicly accessible sources of professional information, and joint marketing partners.
Personal Data that we may collect, depending on the particular purpose/s for the realization of which your Personal Data may be processed as described in the below section “HOW WE USE PERSONAL DATA”, includes:
- Name and surname
- Your occupation, specialization and name and address of the healthcare institution in which you are employed
- Contact information (postal address, phone/mobile phone numbers, email address and/or fax number)
- Your preferred language
- Professional photograph
- Your interests (such as in health care topics about which you request information from us)
- Professional biography including data related to your education, licensures, specialties, professional affiliations (e.g., memberships in medical societies or HCP networks), publications, credentials, and other professional achievements
- Data related to your use of our products, your interactions with us, your preferred method of communications with us, and services for those you care for
- Financial and banking data that you provide to us to pay you for services and provide reimbursement for professional fees, travel, accommodation and out of pocket expenses
- National ID number, passport number, tax identification number
- Travel preferences.
When you are asked to provide Personal Data, you may decline. But if you choose not to provide data that is necessary for us to provide requested services/information or perform our contractual obligations, as applicable, we may not be able to provide you those services/information or perform those contractual obligations.
If you provide or permit us to collect any Personal Data relating to another person, including adverse event data, you are telling us that you have the authority to share that data and to permit us to use the data as described in this HCP Privacy Notice.
HOW WE USE PERSONAL DATA
We may use Personal Data in order to:
- Interact and engage with you when we have a contractual relationship or a legitimate interest. Interacting and engaging with you includes:
- Responding to your inquiries and your requests
- Enforcing the contractual terms and conditions that govern our relationship with you (e.g., medical events, publications, advisory meetings, etc.) and, where applicable, paying you for defined or agreed upon services or reimbursing your expenses, planning calls, meetings, trips and other related interactions with you, sending administrative information to you, and documenting our interactions with you
- Creating and maintaining Pfizer’s database of health care providers to identify and, if applicable, engaging with you (by digital or other means) as a scientific expert or a key opinion leader in various health care fields based on your professional expertise and opinions, and where applicable, your past interactions with us, such as:
- inviting you to attend congresses/panels, HCP professional meetings and educational activities
- reaching out to you for your professional expertise by communicating information about our products through our professional representatives or in the context of surveys relating to pharmaceutical products or services.
- Operate our business to comply with our legal obligations, for statistical purposes or to meet our legitimate interests in maintaining our business. Operating our business includes:
- Complying with our regulatory monitoring and reporting obligations, including those related to adverse events, product complaints and product safety
- Verifying your eligibility to access certain products, services and data that may be provided only to licensed HCPs or otherwise conducting background checks to ensure we are not precluded from working with you
- Conducting training and ensuring quality control
- Detecting, preventing, or investigating misconduct
- Complying with anti-corruption and transparency obligations
- Analysing and/or predicting HCPs preferences in order to identify aggregated trends to develop, improve or modify our products, services and business activities, for example by conducting customer satisfaction surveys and market research surveys
- Protecting our rights, privacy, safety or property, and/or that of our affiliates, you or others.
- Provide you, by digital means or otherwise (including e-mails, SMS/MMS messages, WhatsApp, Viber and/or any other applications/collaboration platforms allowing messaging and/or video/audio communication), with (1) health, medical and scientific information considered by Pfizer as potentially relevant for you and your work/professional needs and aspirations, (2) marketing/promotional information concerning Pfizer's products and/or professional activities, (3) educational and/or promotional materials, which may be personalized to your professional area and interests, as well as to (4) send you invitations and enable access to webinars, (5) communicate with you regarding programs, events and activities sponsored by Pfizer and/or third parties, and (6) enable your access to PfizerPro website and/or other professional services of Pfizer, when we have your consent (or based on our legitimate interest, when permitted by law). Note that you always have the right to withdraw your consent at any time, as well as to object to processing of your Personal Data for direct marketing purposes (including also related profiling, if applicable), by contacting us as indicated in the “Contact Us” section.
HOW WE DISCLOSE PERSONAL DATA
We may disclose Personal Data, when permitted by law, i.e., when we have an adequate legal basis for doing so, as follows:
- To other Pfizer companies (visit www.pfizer.com for a list of our companies) for the purposes described in this HCP Privacy Notice
- To our third party service providers, to provide services such as data analysis, data technology and related infrastructure provision, customer service, auditing and other services (for example, providers of WhatsApp/Viber services)
- To comply with a regulatory requirement, judicial proceeding, court order, government request, or legal process served on us
- To other companies with which we collaborate regarding joint development, distribution and/or marketing of particular products or services
- To data companies providing information services in the healthcare sector to ensure your data remains up to date and accurate
- To take legal action or otherwise protect the safety, rights, or property of our customers, the public, Pfizer and our affiliates
- To prepare, complete and implement any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings).
LEGAL BASIS FOR DATA PROCESSING
The legal basis for processing your Personal Data may be the fulfilment of legal obligations (such as payment of taxes related to payment of your fees, if applicable), performance of an agreement entered into with you (and/or undertaking measures upon your request prior to entering into an agreement) if applicable, your consent for a particular processing of your Personal Data and/or protection of lawful rights and interests realized by Pfizer, its affiliated entities and/or third parties provided that your interests and fundamental rights do not override those interests.
If/whenever consent is a legal basis for your Personal Data's processing, you have the right to withdraw such consent at any time by contacting us as indicated in the “Contact Us” section, whereas such withdrawal does not affect lawfulness of your Personal Data's processing performed prior to such withdrawal.
INDIVIDUAL RIGHTS
If you would like to exercise, to the extent applicable, any of your rights concerning processing of your Personal Data by Pfizer, i.e., if you would like to request to be informed about the data we hold on you, to access to and review, correct, update, suppress, restrict, deletion of your Personal Data in our possession, withdraw your previously provided consent or submit objection to particular processing of your data, you may contact us as indicated in the “Contact Us” section. We will respond to your request consistent with the applicable law.
In your request, please tell us what Personal Data you would like to have changed, whether you would like to have it suppressed from our database, or otherwise let us know what limitations you would like to put on our use of it. For your protection, we may need to verify your identity before implementing your request. We will try to comply with your request as soon as reasonably practicable.
In addition to all the above rights, you are also entitled, if you think that a particular processing of your Personal Data is not compliant with applicable law, to file a complaint with the competent data protection authority, i.e., with the Agency for Protection of Personal Data, Dubrovačka 6, Sarajevo (“Agency”).
Please note that we may need to retain certain Personal Data for, if/to the extent applicable, recordkeeping purposes and/or to complete any transactions that you began prior to requesting a change or deletion.
DATA SECURITY
We seek to use reasonable organizational, technical and administrative measures to protect your Personal Data. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.
RETENTION PERIOD
We will retain your Personal Data for as long as needed or permitted in light of the purpose(s) for which it was obtained and as outlined in this Privacy Notice, or even permanently if such obligation is envisaged by applicable law. The criteria used to determine our retention periods include: (i) the length of time we have an ongoing relationship with you and provide our products, services or contents to you; (ii) whether there is a legal obligation to which we are subject; or (iii) whether retention is advisable in light of our legal position (such as in regard to the enforcement of applicable contract terms, applicable statutes of limitations, litigation or regulatory investigations).
If/whenever your consent is a legal basis for your Personal Data's processing, your Personal Data can be retained for as long as there is a valid consent for their processing. If such consent is withdrawn, which you are entitled to do at any moment, as already mentioned in this Privacy Notice, Pfizer shall stop processing your Personal Data upon such withdrawal, unless there is another legal basis for the respective processing.
CROSS BORDER TRANSFERS
The data we collect may be stored and processed in any country where we have facilities or in which we engage service providers, including in the U.S. and where our affiliates operate, but always in accordance with the requirements prescribed by law of Bosnia and Herzegovina.
If data are transferred from Bosnia and Herzegovina to other countries which are not regarded as countries with adequate data protection systems, Pfizer will undertake additional safeguards to ensure that the processing of the Personal Data is compliant with relevant standards and rules governed by legislation applicable in Bosnia and Herzegovina (for example, by obtaining guarantees of a data recipient is other country in terms of protection of privacy and fundamental rights and freedoms of individuals). To obtain a copy of these measures/further details regarding these measures, if applicable, please contact us as stated in the section “Contact Us”.
DATA OF MINORS
If you are providing us with Personal Data of individuals under the age of eighteen (18), you represent that you have the appropriate authority to do so, and that you can demonstrate such authority to Pfizer upon request.
UPDATES
From time to time, we will update this HCP Privacy Notice. Any changes will become effective when we post the revised Privacy Notice at privacycenter.pfizer.com. This notice was last updated as of the “Last Updated” date shown above.
CONTACT US
The company responsible for collection, use and disclosure, i.e., for processing of your Personal Data under this Privacy Notice, and which, as such, has the capacity of the data controller for the respective processing, is:
Pfizer BH d.o.o. Sarajevo, Fra Anđela Zvizdovića 1.
If you have questions about this Privacy Notice, or if you would like to request to exercise any individual rights, please write to the above address.
DISCLOSURES OF TRANSFER OF VALUE
If/to the extent applicable, Pfizer company in the country of your professional practice will make public disclosures of the transfers of value that you receive from any Pfizer company according to the EFPIA Transparency Code of Conduct, i.e., Code on Public Disclosure of Transfers of Value to Healthcare Professionals and Health Care Organizations, adopted by UIPL (Association of Innovative Manufacturers of Medicines) (hereinafter: Code), and/or applicable local law (such as payment of professional fees, travel, accommodations and out of pocket expenses).
Unless otherwise required by law, Pfizer will publish total amount of all payments and transfer of values which you have, if applicable, received from Pfizer in a calendar year per payment type, in line with the Code. Information will be published on Pfizer web pages on annual basis, not later than 30 June for previous calendar year. Information will be available for the period of 3 years from the moment of first publishing, after which it will be deleted.