hamburger overlay

South Africa Privacy Policy & PAIA Manual

Privacy Policy

Thank you for visiting a Roche website or interacting with us via e-mail and other social media sites. This policy describes how Roche Diabetes Care South Africa Proprietary Limited and its affiliates (“Roche”) processes personal information (including sensitive personal information) collected or received from you.

At Roche, we understand that protecting the privacy of visitors to our web sites is very important and that information about your health is particularly sensitive. That is why we have taken the necessary steps to meet local data privacy requirements. We treat your “Personal Data” according to the ”Roche Directive on the Protection of Personal Data”, and to the laws of the South Africa and other applicable local laws which regulate the storage, processing, access and transfer of personal data.

Roche websites that display this privacy statement (“Statement”) and ask for any information from you, are committed to collecting, maintaining, and securing personal information about you in accordance with this Statement, as well as applicable laws, rules and regulations. This Statement applies to personal information (as defined below) collected from Roche online resources and communications (such as websites, e-mail, and other online tools) that display a link to this Statement.

This Statement does not apply to personal information collected from offline resources and communications, except in cases where such personal information is consolidated with personal information collected by Roche online. This Statement also does not apply to third-party online resources to which Roche’s websites may link, where Roche does not control the content or the privacy practices of such resources.

We only collect personally identifiable information about you if you choose to give it to us. We do not share any of your personally identifiable information with third parties for their own marketing use unless you explicitly give us permission to do so.

Please review this Privacy Statement to learn more about how we collect, use, share and protect personal information online.

Please be aware that we may use service providers and data processors or any third party working on our behalf and/or authorized by Roche. The services can include hosting and maintenance services, analysis services, e-mail messaging services, delivery services, handling of payment transactions, solvency check and address check, etc. These third parties are granted access to such personal information they require in order to be able to carry out the particular service. These third parties are contractually obliged to treat such information in the strictest confidence. It is also contractually forbidden for them to use the information in any other way than required. The necessary steps are taken to ensure that the third party companies working on our behalf protect the confidentiality of your personal information.

Where personal information is stored or processed outside of the country of collection (whether by us or any third party as outlined above), it is subject to the laws of that foreign jurisdiction, and maybe accessible to that jurisdiction’s government, courts, or law enforcement or regulatory agencies.

Information Collected

There are two general methods that Roche uses to collect information from you online:

Information We Get

- Personal identifiable information: You can visit our websites without providing any personal information. We may collect your personally identifiable information (such as name and surname, address, telephone number, e-mail address or other identifying information) only when you choose to submit it to us. This includes information provided to us when you are in contact with us and provide the information to us. We may also collect health information about you that you provide by responding to our questions or surveys.

- Aggregate information: In some cases we also remove personal identifiers from data you provide to us and maintain it in aggregate form. We may combine this data with other information to produce anonymous, aggregated statistical information (e.g. number of visitors, originating domain name of the internet service provider), helpful to us in improving our products and services.

Automatically Collected Information

We can also automatically receive certain types of information whenever you interact with us on our websites and in some e-mails we may send each other. Automatic technologies and services we use may include, for example, web server logs/IP addresses, cookies, web beacons and third party application and content tools.

Web server logs/IP addresses. An IP address is a number assigned to your computer whenever you access the Internet. All computer identification on the Internet is conducted with IP addresses, which allow computers and servers to recognize and communicate with each other. Roche collects IP addresses to conduct system administration and report aggregate information to affiliates, business partners and/or vendors to conduct site analysis and website performance review.

Cookies. A cookie is a piece of information that is placed automatically on your computer’s hard drive when you access certain websites. The cookie uniquely identifies your browser to the server. Cookies allow us to store information on the server to help make the website experience better for you and to conduct site analysis and website performance review. Most web browsers are set up to accept cookies, although you can reset your browser to refuse all cookies or to indicate when a cookie is being sent. Note, however, that some portions of our websites may not work properly if you refuse cookies.

Web Beacons. On certain web pages or e-mails, Roche may utilize a common Internet technology called a "Web beacon" (also known as an "action tag" or "clear GIF technology"). Web beacons help analyze the effectiveness of websites by measuring, for example, the number of visitors to a website or how many visitors clicked on key elements of a site.

Web beacons, cookies and other tracking technologies do not automatically obtain personally identifiable information about you. Only if you voluntarily submit personally identifiable information, such as by registering or sending e-mails, can these automatic tracking technologies be used to provide further information about your use of the websites and/or interactive e-mails to improve their usefulness to you.

Services: We may provide services based on third party applications and content tools on certain Roche websites such as Google Maps or QUARTAL FLIFE. These third parties may automatically receive certain types of information whenever you interact with us on our sites using such third party applications and tools.

Your Choices

You have several choices regarding your use of our websites. You could decide not to submit any personally identifiable information at all by not entering it into any forms or data fields on our websites and not using any available personalized services.

If you choose to submit personal data, you have the right to see and correct your data at any time by accessing the application and to withdraw your consent at any time to Roche’s continued storage and processing of such personal data, by sending an email to midrand.privacydc@roche.com notifying Roche of any such withdrawal. On receipt of such withdrawal, Roche shall cease all further processing of your personal information and shall take steps to dispose of your personal information.

Certain websites may ask for your permission for certain uses of your information and you can agree to or decline those uses. If you opt-in for particular services or communications, such as an e-newsletter, you will be able to unsubscribe at any time by following the instructions included in each communication. If you decide to unsubscribe from a service or communication, we will work to remove your information promptly, although we may require additional information before we can process your request.

As described above, if you wish to prevent cookies from tracking you anonymously as you navigate our websites, you can reset your browser to refuse all cookies or to indicate when a cookie is being sent.

Why we process your personal information

Roche collects personal information from you to:

  • perform our business operations,
  • communicate with you and provide necessary support,
  • provide you with news, special offers and general information about other goods, services and events which we offer that are similar to previous enquiries and or purchased goods or services,
  • provide you with, and improve products and services, and
  • personalise your experience when you use our products and services.Our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it. However, we will normally collect personal information from you only:
  • where we have your consent to do so,
  • where we need the personal information to perform a contract with you, or
  • where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms (for example, in some cases for direct marketing, fraud prevention, network and information systems security).

 

In some cases, we may also have a legal obligation to collect personal information from you or may otherwise need the personal information to protect your vital interests or those of another person.

If we ask you to provide personal information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information).

Similarly, if we collect and use your personal information in reliance on our legitimate interests (or those of any third party), we will make clear to you at the relevant time what those legitimate interests are.

We may process your personal data as required to prepare or protect against legal claims; including litigation, anti-fraud measures, and technical and organisational measures to protect our networks and technology against attacks.

We may process your personal information to the extent necessary for the purposes of preventive medicine, for medical diagnosis, the provision of health care or treatment or the management of health care systems and services pursuant to contract with a health care professional subject to professional secrecy (such as your treating care giver at a hospital).

We may process your personal information for scientific research purposes or statistical purposes in accordance with applicable law, provided it is proportionate to the aim pursued, respects the essence of the right to data protection and provides for suitable and specific measures to safeguard your fundamental rights and interests. As a rule, we will still ask for your consent when we would like you to participate e.g. in a study.

The following sections advise of the reason(s) we rely on for processing your personal information and list the ways that we may use your personal information.

  Legitimate Interest Legal Obligation Consent Contractual
Browsing public pages on our website      
Undertake website administration and personalization      
Managing network and data security      
Logistics planning, demand forecasting, product improvement, management information and research      
Providing customer services to you      
Processing and responding to complaints received from you      
Internal training and monitoring purposes (call recording)      
To detect, investigate and report financial crime (e.g. fraud)      
Registering your interest in products or services      
Marketing Communications      
Contacting you to undertake customer satisfaction surveys, invite you to review a product, invite you to enter a competition or for market research      
Use of the diabetes management system    
Informing you on our website of product safety notices when required      

Further information regarding the processing of personal information that we undertake can be found below, however if you have questions about, or need further information concerning, the legal basis on which we collect and use your personal information, please contact us using the contact details provided at the end.

How we use your personal information

This Privacy Statement explains how we use any personal information we collect about you when you:

  • Browse public pages on our websites
  • Communicate with us by telephone, e-mail, web forms or otherwise in respect of our products and services or during the purchasing of any such products
  • Complain about our services and products
  • Use our diabetes management software
  • Consent to marketing

a) Browse public pages on our websites

If you browse public pages on our websites we collect and process only non-sensitive information about you.

b) Communicate with us by telephone, e-mail, webforms or otherwise in respect of our products and services

If you communicate with us by telephone, e-mail, webforms or similar, we will process your contact details and the personal information you give to us. We will process such information only to the extent required to answer your enquiry, and will delete the information when no longer required as evidence (normally three years), unless you have consented for us to use your data for other purposes, of which its purpose will be specified at time of you giving us consent.

We record calls to our customer services team, when you have consented, for quality and training purposes. We only retain records of where you have provided consent for as long as it is valid.

c) Complain about our services and products

When we receive a complaint about a product or service from a person we create a file containing the details of the complaint, including the identity of the complainant. It may contain health related information. We will only use the personal information we collect to process the complaint.

We will keep personal information contained in complaint files in line with our retention policy. This means that information relating to a complaint will be retained for two years from closure. It will be retained in a secure environment and access to it will be restricted according to the ‘need to know’ principle.

d) Use our diabetes management software or app

Roche offers services to help you better understand your diabetes. These include diabetes management services such as e.g. mySugr. You will be notified of the service’s privacy statement, terms of conditions of use at the point of setting up an account.

e) Consent to marketing

We will only send you marketing communications when you have provided your consent and we will only share your data with a third party if we have your consent. We will make this clear at the time you provide your consent.

Security

Roche uses technology and security precautions, rules and other procedures to protect your personal information from unauthorized access, improper use, disclosure, loss or destruction. To ensure the confidentiality of your information, Roche uses also industry standard firewalls and password protection.

It is, however, your personal responsibility to ensure that the computer you are using is adequately secured and protected against malicious software, such as trojans, computer viruses and worm programs. You are aware of the fact that without adequate security measures (e.g. secure web browser configuration, up-to-date antivirus software, personal firewall software, no usage of software from dubious sources) there is a risk that the data and passwords you use to protect access to your data, could be disclosed to unauthorized third parties.

Use of Data

Roche, including the subsidiaries, divisions and groups worldwide and/or the companies appointed to distribute our products and/or to perform services on our behalf and/or authorized by Roche will use any personally identifiable information you choose to give us to comply with your requests. We will retain control of and responsibility for the use of this information. Some of this data may be stored or processed at computers located in other jurisdictions, such as the United States, whose data protection laws may differ from the jurisdiction in which you live.

In such cases, we will ensure that appropriate protections are in place to require the data processor in that country to maintain protections on the data that are equivalent to those that apply in the country in which you live. The information, which is also used for different purposes (performance management, succession decisions or development actions), will be helpful for us to better understand your needs and how we can improve our products and services. It helps us also to personalize certain communications with you about services and promotions that you might find interesting. For example, we may analyze the gender or age of visitors to our websites about a particular medication or disease state, and we may use that analysis of aggregate data internally or share it with others.

Data Sharing and Transfer

Roche shares personally identifiable data about you with various third party companies or agents doing technological maintenance or working with Roche to help fulfill business transactions, such as providing customer services, sending marketing communications about our products, services and offers. We may also share personally identifiable data with Roche company's subsidiaries and affiliates. All these companies and agents are required to comply with the terms of our privacy policies.

We may also disclose personally identifiable information for the following but not limited purposes:

  • in connection with the sale, assignment or other transfer of the business of the website to which the data relates;
  • to respond to appropriate requests of legitimate government agencies or where required by applicable laws, court orders, or government regulations; or
  • where needed for corporate audits or to investigate or respond to a complaint or security threat.

No Third-Party Direct Marketing Use. We will not sell or otherwise transfer the personally identifiable information you provide to us at our websites to any third parties for their own direct marketing use unless we provide clear notice to you and obtain your explicit consent for your data to be shared in this manner.

E-mail a Friend or Colleague. On some Roche websites, you can choose to send a link or a message to a friend or colleague referring them to a Roche website. E-mail addresses you may provide for a friend will be used to send your friend information on your behalf and will not be collected or used by Roche or other third parties for additional purposes.

Google Analytics. Roche websites may use Google Analytics, a web analytics service provided by Google, Inc. ("Google"). Google Analytics uses "cookies", which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google on servers in the United States. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will not associate your IP address with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, however, as mentioned above please note that if you do this you may not be able to use the full functionality of a Roche website. By using a Roche website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.

Links to Other Sites

Our websites contain links to a number of other websites that may offer useful information to our visitors. This Privacy Statement does not apply to those websites, and we recommend communicating to them directly for information on their privacy policies before providing your personal information. Roche is therefore not responsible for the privacy practices of other parties.

Transfer to other countries

We may transfer and store the personal information we collect about you through the website in servers located outside of your country of residence in countries that may not have the same data protection laws as the country in which you initially provided the information. When we transfer your information to other countries, we will protect that information as described in this Privacy Statement. In particular, we will base such data transfers on adequate standards such as data protection clauses that provide equal or better data protection laws as South Africa. Roche will take reasonable steps to ensure the safety and security of your data.

Privacy Statement for Children

Our websites are addressed to an adult audience. We do not intentionally collect any personally identifiable information from anyone known to be under the age of 18 without the prior, verifiable consent of his or her legal representative. Such legal representative has the right, upon request, to review the information provided by the child and/or to require that it be deleted and refusing the further processing of the information.

Additional Information on Websites

If a website has particular provisions relating to privacy that differ from those stated here, those provisions will be disclosed to you on the page on which personally identifiable information is collected.

Note to Users of Business or Professional Websites

If you have a business or professional relationship with Roche, we may use information you submit on our websites, including websites intended specifically for business and professional users, to fulfill your requests and develop our business relationship with you and the entities you represent. We may also share such information with third parties acting on our behalf and/or providing us services.

Updates to Privacy Statement

From time to time, Roche may revise this Privacy Statement. Any such changes to this Privacy Statement will be promptly communicated on this page. Continued use of our websites after receiving notice of a change in our Privacy Statement indicates your consent to the use of newly submitted information in accordance with the amended Roche Privacy Statement. The effective date of this Privacy Statement is 1st of July 2021.

Access to your personal information

You may request confirmation of the personal information Roche holds, access to your personal information, the category or identity of third parties to whom your personal information has been disposed to or the correction and updating of any incorrect, incomplete or excessive personal information.

How to Contact Roche Diabetes Care South Africa

If you have any questions or concerns about privacy or would like to exercise your rights in relation to your personal information, please contact our Information Officer at midrand.privacydc@roche.com or contact us at the address below:

Roche Diabetes Care South Africa (PTY) LTD Hertford Office Park, 90 Bekker Road, Vorna Valley Johannesburg South Africa Tel: (+27) 011-504 4600 Midrand.privacydc@roche.com

If you are not satisfied with the way Roche handles your data or responds to your requests, you may also lodge a complaint with the Office of the Information Regulator at the following email address: complaints.IR@justice.gov.za.

Unless explicitly stated otherwise, this Privacy Policy applies to F. Hoffmann-La Roche Ltd or F. Hoffmann-La Roche Ltd Websites.

This website contains information on products, which are targeted to a wide range of audiences and could contain product details or information otherwise not accessible or valid in your country. Please be aware that we do not take any responsibility for accessing such information, which may not comply with any valid legal process, regulation, registration or usage in the country of your origin. For any further information, please contact the authorized local representative in your country.

The information provided on this website are product related information for general information purpose only and shall not be construed as giving any advice or making any recommendation. The products information contained herein does not constitute an offer of or solicitation for the purchase or disposal of, trading or any transaction in any Roche products. You must not rely on this information for purchase decisions and a prior consultation with a qualified healthcare professional is required before considering any treatment.

The products information contained herein shall not be construed as a promotion or solicitation for any related products.

 

Download the Roche Diabetes Care POPIA Manual here.