Data Privacy Statement

Information on data privacy Content With this document, Bayer Zydus Pharma Private Limited and Bayer Pharmaceuticals Private Limited (hereinafter “us”, “our” or “we”) wishes to provide you with information on how we handle your personal data that we have purchased from a commercial data provider and to obtain your consent for specific purposes as outlined below.

  1. How we collect your data We will, wherever possible, collect information about you directly from you. However, on some occasions it may be collected from other sources, such as: Agents or service providers including third party data providers and customer relationship management service providers; Publicly available directories and listings such as telephone directories; Newspapers, magazines, professional journals and the electronic media; The internet and other electronic communications such as articles and information pieces in which you feature such as a health information site or a medical professional site; The date, time and domain from which you access a Bayer website; Personal interactions and/or communications with Bayer staff.

We may access personal data about you from our business partner Veeva Systems Inc. If you want to know more about how Veeva Systems Inc. collects this data in their own responsibility, please feel free to read Veeva Systems Inc.’s Data Privacy Statement.

The personal information Bayer collects may vary depending on your particular interaction with Bayer and will be for a legitimate business purpose.

  1. What data do we collect We are getting access to the following categories of your personal data:

Identification Data Contains information that is used to identify you such as for example your full name, academic title, date of birth, national doctor’s ID number or other professional identifiers, postal and workplace address, other technical digital identifiers. Contact Data Information that is used to contact and interact with you, such as for example your telephone-, mobile-, or fax numbers, address, email, or other digital contact information. Scientific Expertise Data Includes information about your professional and medical expertise such as for example, profession, position, and function, specialty, areas of expertise, role in the scientific community, educational background and academic credentials, place of work. Scientific Activities Data on your professional and scientific activities, such as for example scientific publications, participations in research projects, conference or event presentations and participation, clinical trial involvement, research and treatment areas, treatment preferences, payment, and referral information. Activities in scientific communities, professional, and social networks Data on your networking activities and collaborations in scientific communities, organisations, and professional networks for example hyperlinks to your profile on social media and networking sites, photos, published professional activities on social networks.

  1. Legal Basis Unless otherwise indicated in the following sections, the legal basis for the handling of your personal data results from the fact that it is necessary to pursue our legitimate interest to promote our products and services, (Art. 6(1)(f) General Data Protection Regulation).

  2. Handling of personal data Your personal data will be used for the following purposes:

    a. Maintain customer relationship management

We maintain a customer relationship management system where we store personal data about you:

Analyze customer relations: We use your categories of personal data listed above in order to be able to better understand your interests and inform you about our products and services that might interest you.

Improve customer collaboration: In order to manage our collaboration with you in an effective way and to support successful market development of our products and services, we try to better understand which scientific/medical topics you are particularly interested or involved in and which organizations you collaborate with, e.g. information about your area of medical expertise, your scientific activities such as publication of scientific articles, participation in research projects and professional congresses.

b. Conduct market research studies

We work together with fully independent market research agencies, who, on our behalf, conduct market research studies globally, focused on our scientific interests and products. We may share your contact information with these market research agencies in order to conduct market research studies that are specific to our customers.

c. Deliver marketing/medical communications

We may use your contact information to communicate with you through phone calls, direct mail, email or other electronic communication (e.g., fax, chats on websites, text messages, messenger messages or remote detailing/incl. customer services on demand) in order to deliver marketing/medical communications. We might use marketing/medical communications to provide information about services, products or events related to your medical interest or to collect feedback on our products and services. This may include displaying customized advertisements tailored to your interests to you on our or other websites and apps. However, marketing/medical communications via e-mail or other electronic communications (“Electronic Marketing/Medical Communications”) as well as via phone calls are subject to you providing your consent, (Art. 6(1)(a) General Data Protection Regulation).

d. Analyze your use of our Electronic Marketing/Medical Communications

In order to customize our Electronic Marketing/Medical Communications to meet your needs and preferences and subject to you providing your consent (Art. 6(1)(a) General Data Protection Regulation), we analyze your use of our Electronic Marketing/Medical Communications, for example whether you opened and how you used our Electronic Marketing/Medical Communication (e.g. which links you clicked).

  1. Transfer of personal data 5.1 Commissioned Processing

We use specialized service contractors that help us providing our services. Such service contractors are carefully selected and regularly monitored by us. Based on respective data processor agreements, they will only process personal data upon our instruction and strictly in accordance with our directives.

5.2 Third Parties

We transfer or give access to your personal data to trusted third-party service providers in the following circumstances:

a. We may share your Contact Information with fully independent market research agencies.

b. We may transfer your above-referenced personal data to other Bayer affiliates for the purposes specified above. However, other Bayer affiliates will only directly deliver corresponding marketing communications via e-mail or other electronic communications to you, if you provide your consent below.

c. We may also transfer your above-referenced personal data to other partners that need to be involved in managing a service or communication towards you, e.g. hosting of data, hotels or travel agencies.

We might also disclose or share your personal data to third parties in the following exceptional cases:

with a prospective buyer in case of an acquisition, merger, or any other type of corporate or asset transition involving a change of ownership or control concerning us, our brands, products, or our services.

when we believe in good faith that disclosure is necessary to establish or exercise our legal rights or defend against legal claims, protect your safety or the safety of others, investigate fraud, or respond to a government request

when required by law we may disclose your personal data to public authorities such as health authorities, tax authorities, and law enforcement authorities

to support legal decisions and to pursue or defend against legal claims, we may share your personal data with external lawyers.

All sharing of data collected is based on our legitimate interest or a specific legal requirement.

5.3 Transfer to non-EU countries

Your data may in part also be transferred and processed in countries outside the European Economic Area (“EEA”), which may have a lower data protection level than European countries. Wherever required, we will ensure that a sufficient level of protection is provided for your data, e.g. by concluding specific agreements with the respective data importer. Such data transfers are only carried out in accordance with applicable data privacy laws.

Transfers inside the Bayer Group are based on a Master Data Sharing Agreement, which includes the Standard Contractual Clauses published by the European Commission as a safeguard for the international transfers. You can access the clauses on this site: https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en

  1. Retention period for personal data We retain your personal data as long as is necessary for the continuous customer relationship with you as well as for further (3 years) after you actively ended the customer relationship or there has been no activity for (2 years), whichever happens first. Thereafter we anonymize the data so that they do no longer relate to you. We may retain your personal data for a different retention period, where otherwise provided by law.

  2. Information regarding your rights The following rights are in general available to you according to applicable data privacy laws:

a. Right of information about your personal data stored by us;

b. Right to request the correction, deletion or restricted processing of your personal data;

c. Right to object to a processing for reasons of our own legitimate interest, public interest, or profiling, unless we are able to prove that compelling, warranted reasons superseding your interests, rights and freedom exist, or that such processing is done for purposes of the assertion, exercise or defense of legal claims;

d. Right to data portability;

e. Right to file a complaint with a data protection authority;

f. You may at any time with future effect withdraw your consent to the collection, processing and use of your personal data. If you wish to withdraw your consent, you can do so by contacting us as described below.

If you wish to exercise your rights, please address your request to:

Grievance Officer, Bayer Group of Companies in India, Bayer House, Central Avenue, Hiranandani Estate, Thane (West) – 400 607 India. Tel. No.: +91 22 2531 1234; E-mail: dpo_india@bayer.com

  1. Amendment of Privacy Statement We may update our Privacy Statement from time to time. Updates of our Privacy Statement will be published on our Website. Any amendments become effective upon publication on our Website. We therefore recommend that you regularly visit the site to keep yourself informed on possible updates.