Eliquis Patient Support Program - Privacy Policy

Compliant with Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486) and relevant data protection regulations


Registration and participation in the Eliquis Patient Support Program will require the User to agree to separate corresponding terms and conditions, and mechanics; and privacy consent to the processing of personal information and sensitive personal information, as defined under applicable laws, which may be amended or replaced from time to time.

GENERAL PROVISIONS

  1. This Privacy Policy ("Policy") is established by Pfizer Corporation Hong Kong Limited ("Pfizer" or "Data Controller") and governs all personal data processing activities related to the Eliquis Patient Support Program ("Program").

  2. This Policy explains how we collect, process, store, use, and transfer your personal data across borders, while clarifying your rights under applicable laws.

DEFINITION AND SCOPE OF PERSONAL DATA

  1. As used in this Policy: “Users” means an individual patient who (a) have already been prescribed Eliquis/Apixaban in Hong Kong public hospitals or (b) voluntarily subscribes to the Eliquis PSP; and “personal data” means data, whether true or not, about a customer who directly or indirectly, and as defined by the applicable Laws in Hong Kong can be identified: (a) from that data; or (b) from that data and other information to which we have or are likely to have access.

  2. As required for implementing the Program, the following personal data will be collected in accordance with the minimum data principle:

    • Identity Information: Full name, last 4 digits of ID number, email address.

    • Contact Details: Mobile number.

    • Medical Information: Valid Eliquis prescription (issued by Hong Kong public hospitals).

    • Purchase Records: Date, quantity, receipt, and photos of Eliquis package box.

PURPOSE OF DATA PROCESSING

  1. Your personal information the Company processes only include the information submitted by yourself via the App.

  2. Your personal data will be strictly used for the following purposes only:

    • Verifying prescription and purchase records.

    • Calculating and issuing "Buy Six, Get One Free" benefit.

    • Sending program notifications via SMS/App (e.g., approval status, redemption reminders).

    • Anonymous statistics to assess project size and estimate the number of operational staff required.

DATA RECIPIENTS AND CROSS-BORDER TRANSDER

  1. Your personal data will involve different Data Recipients with different roles:
    - Data Controller: Pfizer Corporation Hong Kong Limited.
    - Server Location: Singapore (all data stored on Singapore-based servers).
    - Third-Party Processor: Pfizer authorizes IQVIA Solutions Enterprise Management Consulting (Shanghai) Co., Ltd. (based in Mainland China) to process patient data

  2. Data Transfers: Your data may be transferred from Hong Kong to Singapore and Mainland China for Purposes of Data Processing described in clause 6 above.

WITHDRAWING YOUR CONSENT

  1. The consent that you provide for the collection, use, and disclosure of your personal data will remain valid until such time it is withdrawn by you. You may withdraw consent and request us to stop using your personal data for any or all of the purposes listed submitting your request via email to our authorized Data Protection Officer at the contact details provided below.

  2. Upon receipt of your written or Program request to withdraw your consent, we may require reasonable time (depending on the complexity of the request and its impact on our relationship with you) for your request to be processed and for us to notify you of the consequences of us acceding to the same, including any legal consequences which may affect your rights and liabilities to us. In general, we shall seek to process your request within ten (10) business days of receiving it.

  3. Whilst we respect your decision to withdraw your consent, please note that depending on the nature and scope of your request, we may not be in a position to continue providing our services to you and we shall, in such circumstances, notify you before completing the processing of your request. Should you decide to cancel your withdrawal of consent, please inform us via email to our Data Protection Officer at the contact details provided below.

  4. Please note that withdrawing consent does not affect our right to continue to collect, use and disclose personal data where such collection, use, and disclosure without consent is permitted or required under applicable laws.

ACCESS TO AND CORRECTION OF PERSONAL DATA

  1. If you wish to make (a) an access request for access to a copy of the personal data which we hold about you or information about the ways in which we use or disclose your personal data, or (b) a correction request to correct or update any of your personal data which we hold about you, you may submit your request via email to our Data Protection Officer at the contact details provided below.

  2. We will respond to your access request as soon as reasonably possible. Should we not be able to respond to your access request within thirty (30) days after receiving your request, we will inform you via email within thirty (30) days of the time by which we will be able to respond to your request. If we are unable to provide you with any personal data requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under applicable law in Hong Kong).

  3. We will respond to your correction request as soon as reasonably possible. Should we not be able to correct the correction request within ten (10) days after receiving your request, we will inform you via email of the time by which we will be able to correct your correction request. If we are unable to make a correction requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under applicable law in Hong Kong).

RETENTION OF PERSONAL DATA

  1. We may retain your personal data for as long as it is necessary to fulfill the purpose for which it was collected, or as required or permitted by applicable laws.

  2. We will cease to retain your personal data or remove the means by which the data can be associated with you, as soon as it is reasonable to assume that such retention no longer serves the purpose for which the personal data was collected, and is no longer necessary for legal or business purposes, and has fulfilled the requirements of the retention period as required in the applicable laws.

PROTECTION OF PERSONAL DATA

  1. To safeguard your personal data from unauthorized access, collection, use, disclosure, copying, modification, disposal, or similar risks, we have introduced appropriate administrative, physical, and technical measures such as up-to-date antivirus protection, encryption and the use of privacy filters to secure all storage and transmission of personal data by us, and disclosing personal data both internally and to our authorized third party service providers and agents only on a need-to-know basis.

  2. You should be aware, however, that no method of transmission over the Internet or method of electronic storage is completely secure. While security cannot be guaranteed, we strive to protect the security of your information and are constantly reviewing and enhancing our information security measures.

DATA PROTECTION OFFICER

  1. You may contact our Data Protection Officer if you have any inquiries or feedback on our personal data protection policies and procedures, or if you wish to make any request, in the following manner:
    Email to the authorized Third-Party Processor IQVIA via Email eliquispsp@iqvia.com

EFFECT OF POLICY AND CHANGES TO POLICY

  1. We may update this policy; material changes will be notified via App/SMS.