September 1, 2024

Novartis considers privacy as a very important matter. Accordingly, Novartis is pursuing the greatest transparency concerning its processing of personal information.

Novartis Pharmaceuticals Canada Inc. (“Novartis”) is responsible for the processing of your personal information as it decides why and how it is processed. It may exercise this responsibility alone or jointly with other company(-ies) in the Novartis group. In this Privacy Notice, “we” or “us” refers to Novartis Pharmaceuticals Canada Inc.

We are committed to ensuring that any personal information we receive is protected and processed in accordance with applicable data protection laws and Novartis policies and standards. 

For the purpose of the scope of this Privacy Notice, third parties are as follows:

  • Suppliers: An external natural or legal person/entity outside the Novartis Group from whom Novartis sources goods or services. This includes, for example:
    i.    Contract Manufacturing Organizations (CMOs)
    ii.    Institutions and collaborators carrying out research for or on behalf of Novartis, where Novartis is acting as the sponsor and paying for the research, including collaborators of both Contract Research Organizations (CROs) and Academic Research Organizations AROs)
    iii.    Third parties that handle or distribute Novartis products (i.e. logistics services) where the ownership of the products is not transferred to the third party service provider
    iv.    HCPs acting as "third parties" only, i.e. where they provide goods or services against a fee for a service beyond their profession as an HCP, such as app developers or commercial/marketing consultants, etc. (otherwise HCPs are out of scope).
  • Business Development & Licensing (BD&L): Any third party with whom a product in-licensing agreement has been contracted with Novartis.
  • Distributors and Wholesalers: Any third party that imports and/or resells for its own business purposes Novartis Products (whether or not they provide promotion services for the specific Novartis Products on behalf of Novartis).
     

The purpose of this Privacy Notice is to clarify the way Novartis is processing personal information of representatives and/or employees as contact persons (data subjects) of a third party or its subcontractor (who will be further referred in this Privacy Notice as “you”). 

We invite you to carefully read this Privacy Notice, which sets out how we are processing information that relates directly or indirectly to you, as a natural person, and that allows to identify you (“personal information” The Privacy Notice also explains your rights with respect to the processing of your personal information. 

We have separate privacy notices which govern how we process personal information of our employees, business partners which are not providing services to us, patients and users of our other websites, and you should refer to those where appropriate.


What information do we have about you?

This personal information may either be directly provided by you or provided by our third party (i.e. the legal entity you work for or on behalf of).

We may collect various types of personal information about you, including:

  • your general contact and identification information (e.g. name, first name, last name, gender, date and place of birth, nationality, ID card or passport numbers, email and/or postal address, fixed and/or mobile phone number and car registration number);
  • your function (e.g. title, position and name of company);
  • your financial information (e.g. bank account details, credit worthiness and financial health checks), taxation information (government issued tax ID or account number), information about transactions (delivery and payment history) and background information about your business capabilities and operational performance when you individually act as a third party (e.g. one person company/Sole proprietorship); and  
  • your electronic identification data where required for the purpose of the delivery of products or services to our company (e.g. login, access right, passwords, badge number, IP address, online identifiers/cookies, system activity logs, access and connection times, image recording or sound such as badge pictures, CCTV or voice recordings and meeting recordings).
     

We do not collect any health data unless it is for making reasonable arrangements for a person with disability.

If you intend to provide us with personal information about other individuals (e.g. your colleagues), you must ask the relevant individuals to go through this Privacy Notice available on our corporate website (www.novartis.com/privacy) before providing us with such personal information.


For which purposes do we use your personal information and why is this justified?

We will not process personal information, Novartis may have about you if we do not have obtained your prior consent. However, you have the right to withdraw that consent to the use and communication at any time. To withdraw your consent, Novartis can be contacted as indicated below.

Purposes of the processing

We always process your personal information for a specific purpose and only process the personal information, which is necessary to achieve that purpose. In particular, we process the personal information for any or all of the following purposes:

  • to manage our third parties throughout the relationship; to organize tender-offers, implement tasks in preparation of or to perform existing contracts; to monitor activities at our facilities, including compliance with applicable policies as well as health and safety rules in place; to grant you access to our training modules allowing you to provide us with certain services; to communicate with you during the term of the contract and contact you in case of emergency;
  • to manage our IT resources, including infrastructure management and business continuity; 
  • to preserve Novartis’ economic interests and ensure compliance and reporting (such as complying with our policies and local legal requirements, tax and deductions, managing alleged cases of misconduct or fraud, conducting audits and defending litigation); 
  • to manage mergers and acquisitions involving our company; 
  • for archiving and record-keeping; 
  • for billing and invoicing; 
  • to develop a proximity and trustful professional relationship; 
  • to promote innovation in the pharmaceutical field; to manage Novartis human and financial resources; 
  • to benefit from cost-effective services (e.g. we may opt to use certain platforms offered by suppliers to process data); 
  • to offer our products and services to our customers;
  • to prevent fraud or criminal activity, misuses of our products or services as well as the security of our IT systems, architecture and networks;
  • to sell any part of our business or its assets or to enable the acquisition of all or part of our business or assets by a third party; or 
  • to meet our corporate and social responsibility objectives or 
  • any other purposes imposed by law and authorities.

Who has access to your personal information and to whom are they transferred?

We will not sell, share, or otherwise transfer your personal information to third parties other than those indicated in this Privacy Notice.

In the course of our activities and for the same purposes as those listed in this Privacy Notice, your personal information may be accessed by or transferred to the following categories of recipients, on a need to know basis to achieve such purposes :

  • our personnel (including personnel, departments or other companies of the Novartis group);
  • our independent agents or brokers (if any); 
  • our other suppliers and services providers that provide services and products to us; 
  • our IT systems providers, cloud service providers, database providers and consultants; 
  • any third party to whom we assign or novate any of our rights or obligations; and
  • our advisors and external lawyers in the context of the sale or transfer of any part of our business or its assets.
     

The above third parties are contractually obliged to protect the confidentiality and security of your personal information, in compliance with applicable law. 

Your personal information can also be accessed by or transferred to any national and/or international regulatory, enforcement, public body or court, where we are required to do so by applicable law or regulation or at their request.

Where is personal information stored?

The personal information we collect from you may also be processed, accessed or stored in a country outside the country where Novartis is located, which may not offer the same level of protection of personal information. In that case, we will make sure to protect your personal information by (i) applying the level of protection required under Applicable Privacy Laws, (ii) acting in accordance with our policies and standards and.


How do we protect your personal information?

We have implemented appropriate technical and organizational measures that are reasonable given the sensitivity of the personal information we collect, use, communicate, store or destroy in order to provide an adequate level of security and confidentiality to your personal information. 

The purpose thereof is to protect it against accidental or unlawful destruction or alteration, accidental loss, unauthorized disclosure or access and against other unlawful forms of processing.


How long do we store your personal information?

We will only retain your personal information for as long as necessary to fulfil the purpose for which it was collected or to comply with legal or regulatory requirements.

The retention period is the term of your (or the third party’s) relevant commercial agreement with Novartis plus the period of time until the legal claims under such commercial agreement become time-barred, unless overriding legal or regulatory schedules require a longer or shorter retention period. When this period expires, your personal information is removed from our active systems.

Personal information collected and processed in the context of a dispute are deleted or archived (i) as soon as an amicable settlement has been reached, (ii) once a decision in last resort has been rendered or (iii) when the claim becomes time barred.


What are your rights and how can you exercise them?

You may exercise the following rights under the conditions and within the limits set forth in the law:

  • the right to be informed about what personal information we have about you and how we process your personal information;
  • the right to access your personal information as processed by us and, if you believe that any information relating to you is incorrect, obsolete or incomplete, to request its correction or updating;
  • the right to request the erasure of, or the de-indexation of, your personal information or the restriction thereof to specific categories of processing;
  • the right to withdraw your consent at any time, without affecting the lawfulness of the processing before such withdrawal;
  • the right to request its portability, i.e. that the personal information you have provided to us be returned to you or transferred to the person of your choice, in a structured, commonly used and machine-readable format without hindrance from us and subject to your confidentiality obligations; and

If you have a question or want to exercise the above rights, please click here.

If you are not satisfied with how we process your personal information, you may address your request to our data protection officer at  [email protected] or write to Data Privacy Office, Novartis Pharmaceuticals Canada, 700 St-Hubert, Montreal, Quebec, H2Y 0C1. 

In any case, you also have the right to file a complaint with the competent data protection authorities, in addition to your rights above.


How will you be informed of the changes to our Privacy Notice?

We may change or update this Privacy Notice from time to time by posting a new privacy notice in our procurement systems or our corporate website (www.novartis.com/privacy). Please keep checking this Privacy Notice occasionally so that you are aware of any changes.