PRIVACY POLICY

EFFECTIVE SEPTEMBER 2022

This Privacy Policy (“Policy”) of Pfizer Zona Franca, S.A. (“Pfizer”), a company organized and existing under the laws of Costa Rica, domiciled at San José, Escazú, San Rafael, Avenida Escazú, Torre Lexus, seventh floor applies only to information Pfizer collects through the following website: www.pmiform.com/CAC-E (the “Site”).

This Policy details the information we collect, how it will be handled, when and how it may be shared or transferred, your rights related to the collection and processing of such information, your right to access and update such information, and the security measures we use to protect it.

For the purposes of this Policy, the User shall be any natural person, whether or not a healthcare professional, who consults or accesses the Site and/or who uses the services of the Site. 

1. What information do we collect?

PFIZER limits the collection of information to that which is relevant to follow up on your request for medical information, complaint, adverse event or any other matter that is reported through the Site, as well as to document Pfizer’s response to your request. The collection can be done directly or through third parties acting on our behalf. The collection of personal information is always by lawful means, in accordance with the legislation applicable in your country.

1.1. Information provided directly by the User

The User may share information directly, such as their full name, date of birth, identity document, address, telephone, email and information related to Pfizer medications. In some cases, the User may voluntarily provide data related to their health status, for example, when reporting an adverse event related to a Pfizer medication. This information is provided voluntarily by the User to request medical information, make a complaint and/or receive various information about Pfizer medications. In some cases, User requests that do not have complete information may not be addressed or tracked.

If for any reason the User provides information from a third party, it must always do so under its own responsibility, and with the consent of that third party for the provision of their personal information. Pfizer’s processing of that third party’s information will be done under that understanding, in good faith.

1.2. Device Information

Pfizer may automatically collect certain information. as in the case of IP addresses, type of web browser, internet service provider, reference and output pages, device operating system, activity on the Site (including content viewed within the Site), clickstream data or other metadata, for the purpose of trend analysis, administer the Site, improve performance and content and personalize the User experience. This collection of information may be done through commercial technologies, such as cookies or beacons, as explained in the cookies section.

If the User does not want PFIZER to collect and use the information specific to their geographic location, in some cases they may be able to disable the location features on their device. The User can check the device manufacturer’s settings to verify how to do this. 

1.3. Third Party Source Information

Pfizer may receive additional information about the User through consultation with commercially available open or public sources, or from third parties. 

2. Use of Users’ Information

Pfizer uses User information collected on the Site for various purposes, including, essentially, the attention and follow-up of User requests or complaints, to know about adverse effects of medications, to provide medication information requested by the User, respond to comments or inquiries, perform the analysis of trends and interests, administration of the Site, improve the operation and content and personalize the User experience or to ensure compliance with company policies or applicable laws and regulations to protect, enforce or defend rights, security or company property, of the User or third parties.

The information will be kept for as long as necessary to provide the service, support the requested information, comply with legal, regulatory, administrative, banking or compliance obligations, and resolve controversies or disputes and always respecting the limits established in applicable law.

3. Who is the Information shared with?

3.1. Group member companies 

The information described in section 1 above may be shared or commissioned with Pfizer affiliated companies (companies that control, are controlled or have shared control with Pfizer) as well as selected third parties. 

3.2. Service Providers

Pfizer may share the information described in Section 1 above with service providers performing functions on behalf of the Company. Examples of such features include providing customer service, call center, data storage or processing, administrative functions, email response, payment processing, collection management, market research, or business intelligence.

3.3. Compliance

User information may also be shared on the basis of a statutory obligation, in order to comply with a court or administrative order, legal procedure or similar legal process, including disclosure to external auditors or legal advisors; or when we believe in good faith that such disclosure is necessary to protect our rights, protect the safety of the User or the safety of others, investigate or prevent fraud or in response to a government request.

3.4. Business Operations

Pfizer may share User information provided for in Section 1 above in the event Pfizer is a party to a merger, absorption, transformation, acquisition or sale or transfer of shares, or in the unlikely event of an insolvency proceeding.

3.5. With third parties

Pfizer may share Users’ information with third parties for any other purpose that has been reported to the User at the time of collection of the information, or in accordance with the User’s consent.

4. Communication with the User

Pfizer may communicate with User by email, mail, telephone, text messaging systems, chat, chatbot or other means, on a regular basis, to provide products or services requested by User or to periodically report products or services.

5. Information security

Pfizer takes reasonable security measures in accordance with applicable law and industry best practices to ensure that Users’ personal information remains secure and up-to-date. However, no data transmission over the Internet is completely secure, despite our best efforts to protect personal information, we cannot assure or guarantee that it is completely secure, so the User assumes a reasonable level of risk in the processing of their information. In the event of a data security breach, PFIZER shall notify the User of such circumstance, as established by applicable law.

6. Exercise of Rights

Pfizer respects the control that each User has over their personal information, and recognizes the rights of access, rectification, cancellation and opposition, as well as any other that is conferred on the User according to applicable law. At the request of any User and upon confirmation of their identity by verification of their identity document, it will be confirmed whether we maintain or process information that we have obtained from that User. Each User has the right to rectify or update incorrect or incomplete personal information, request the cancellation of their personal information, or request the cessation of their processing (opposition). For this purpose, the User must provide with their request all the information and/or documentation that is necessary for PFIZER to adequately address the requirement, according to the specific right that is intended to be exercised. In certain cases, we will not be able to delete the information, for example, if the request is inconsistent with our legal, contractual, regulatory or compliance obligations, if it prevents PFIZER from exercising rights conferred by law or contract, or if the identity of the applicant cannot be verified or involves a disproportionate cost or effort. However, the respective request will be responded to within the legally established deadlines by providing the relevant explanations.

7. Minors

The Site is intended for a general audience and is not intended for children or children under the age of 18. Pfizer does not collect or process personal information from children or children under the age of 18, unless permitted by law. If a User believes that personal information may have been collected from his/her children or minors about whom he/she is a legal guardian or representative through the Site, he/she may contact Pfizer to delete the personal information of these minors where possible and legally binding.

8. Cookies

PFIZER and/or third parties that may provide content and functionality to our Site use cookies, beacons, and other similar technologies for various purposes, including analyzing trends, administering the Site, monitoring Users’ navigation of the Site, and storing demographic information.

Cookies are small pieces of information that are stored on the hard drive of devices. A cookie allows the organization that placed it on your device to recognize it across different websites, services, devices, and browsing sessions. For example, to identify a User when they return to the Site in order to provide them with a better browsing experience. Cookies owned by third parties may be permitted on the Site, over which we do not control their use or content. Internet browsers allow you to configure settings to accept or reject cookies, or to be informed when a cookie is sent. If the User chooses not to set cookies, they may not be able to fully take advantage of the features and functions of the Site. For more information about cookies, you can visit the Public Inquiry Site www.allaboutcookies.org/es/. This is a third-party site to which we refer for informational purposes, so PFIZER is not responsible for its content, or the actions taken or stopped by the User based on the information contained therein. 

Beacons and similar technologies are pieces of code embedded in web pages and emails, and that communicate with third parties. For example, beacons are used to account for the number of visits to a web page, to send or communicate with cookies, and to study Site usage patterns. In addition, beacons may be included in emails to see if messages have been opened, reacted to, or forwarded.

9. Forums and Social Media

The Pfizer Site or social media may offer access to publicly accessible community forums. User should be aware that any information User provides in these areas is public and may be read, collected, and used by Pfizer and others who have access. If the User does not want this information to be processed by Pfizer, they must proceed to delete it. If you are unable to do so on your own, you may expressly request it from Pfizer. In some cases, your personal information cannot be deleted.

10. Third Party Links

The Pfizer Site or social media may contain links to websites owned or operated or managed by third parties over which Pfizer has no control. Any information User provides to third party websites will be governed by the terms of each website’s privacy policy or Policy, so User is responsible for reviewing those policies before disclosing their information to third party websites. Pfizer assumes no responsibility for the content, actions, or policies of third-party websites. The inclusion of links from third-party websites on our Sites in no way constitutes an endorsement of the content, actions or policies of such websites.

11. Third Party Functionality

Some functionality of the Site may be provided by third parties not connected with Pfizer. These third parties may collect or receive certain information about your use of the Site, including through the use of cookies, beacons and similar technologies. Pfizer is not responsible for the privacy practices of such third parties.

If the User accesses services offered by third parties, such as Facebook, Google or Twitter, through the Site, either to access the Site or to share information about your experience on the Site with others, such services offered by third parties may collect information about the User, including information about activity on the Site, and also, may share your connections to such third parties’ services with respect to your use of the Site, in accordance with their own privacy policies.

12. Modifications to this Policy

This Policy was last updated on the date detailed in the heading. Pfizer reserves the right to modify this Policy at any time. In the event of any material change, we will notify you by notice on the Site. Your subsequent use of the Site will be deemed acceptance of such modifications. Be sure to review this Policy periodically to ensure you are familiar with the most current version. By using the Site after posting changes to this Policy, User agrees to such changes.

13. How to contact Pfizer about these topics

Pfizer is committed to protecting your information. If you have any questions about the processing of your personal information or wish to exercise some of the rights recognized by law and set out in this Policy, you may contact:

Address

Costa Rica, San José, Escazú, San Rafael, Avenida Escazú, Torre Lexus, 7th floor.

Email

[email protected]

14. Governing Law and Forum

This Policy is governed by the laws of the Republic of Costa Rica. Any disputes arising in connection with this Policy will be resolved in the courts of San José.