II. PRIVACY INFORMATION NOTICE FOR: HEALTHCARE PROFESSIONALS (HCP)/EYECARE PROFESSIONALS (ECP) included in Alcon’s CRM system, ordering Alcon product and receiving digital marketing communications With this Privacy Notice, Alcon would like to tell you about the personal data (any information that is capable of identifying you) we collect and use as well as how we ensure we respect your rights. For which reasons do we need to collect and use your data? - We include your personal data in our Customer Relationship Management System (CRM) in order to communicate with you regarding the sale and promotion of our products (this is based on our legitimate interest). - We collect your personal data to deliver you with Alcon products and manage the related payment process (this is necessary for the performance of our contract and based on Alcon’s legitimate interest to sell its products). - If you gave us your consent to do so (on an opt-in or an opt-out basis as required by the laws of the country where you are resident), we will use your personal data for sending you digital promotional communications as per your specific choices. How do we ensure we respect your rights and the law? We make sure we follow these Privacy Principles when we collect and use your personal data: Security: We keep your personal data safe and secure from misuse or unauthorized alteration, loss, or access by using appropriate technical, physical, and organizational measures (such as multifactor password authentication, encryption, access restriction, etc.). Limited Purpose: We collect and use your personal data only as necessary for the purpose. Limited Data: We only collect the personal data that we need. Data Quality: We keep your personal data up to date and ensure that it is accurate. Limited Access: We only give access to your personal data on a strict need to know basis. Limited Retention: We only keep your personal data as long as necessary for the purpose. Lawful Use: We make sure we have a valid and lawful reason to collect and use your personal data (for example, a legitimate interest as referenced above). What personal data do we collect and use? We collect and use the following personal data:
We collect your personal data in order to:
In the case of digital marketing activities we rely on your consent either on an opt-in or opt-out basis, as required by the laws of the country where you are resident. We may also collect and use your personal data as necessary based on our regulatory transparency reporting or other legal requirements. For any voluntary transparency reporting we will ask for your consent. How long do we keep your data? We keep and use your information for as long as necessary for the administration of our relationship unless you ask us to delete your data prior to that date or unless otherwise required under transparency reporting disclosures or other regulatory obligations. Automated Decision Making and Profiling We do not use any automated decision making or profiling. Do you need to provide us with your personal data? You are not obliged to provide us with any personal data. Who do we share your personal data with? If required your personal data can be shared by Alcon with:
We transfer your personal data to other countries outside of the country of residence where you provided your personal data to Alcon, as follows: We transfer your personal data:
What are your rights? Depending on your country of residence and on where your personal data is used, you may have a number of rights. The availability of some of these rights depends on the lawful basis for processing your personal data and your rights may also be subject to certain other legal conditions and restrictions. You may have the right:
Who can you contact regarding your rights? Data Controller: The entity that determines why and how your personal data is processed is called a Data Controller. The Data Controller for the processing of your personal data is: Alcon Vision LLC and its affiliates privacy@alcon.com For Alcon organizations or affiliates located outside of the EEA and for the purposes of the applicability of the General Data Protection Regulation 2016/679, Alcon has elected Alcon Laboratories Belgium BVBA as its legal representative. Data Protection Officer Alcon: privacy@alcon.com Data Protection Authority/Supervisory Authority: The Data Protection Authority/Supervisory Authority for the processing of your personal data is the authority located in the country where you live or work. For individuals resident in the European Union, more information about how to contact these authorities can be found here: https://edpb.europa.eu/about-edpb/board/members_en . |