1. Introduction

This Policy sets out the commitment of Santen Pharmaceutical Asia Pte. Ltd. (“Santen”) to collect and process personal information and sensitive personal information (collectively, "personal data") in accordance with the applicable laws and regulations on data privacy, including the Singapore Personal Data Protection Act 2012 ("PDPA") and its implementing rules and regulations ("PDPA IRA").

2. Definitions and construction

Definitions of certain terms used in this Policy are in Schedule 1.

3. PDPA Exemptions

The PDPA exempts from its application or does not apply to certain personal data and their collection and processing (see Schedule 2). These data and activities are not covered by this Policy.

4. How we collect and process personal data

We may be able to obtain personal data in various ways. These include where a natural or juridical person -

  • 1.Enters a contractual relationship with Santen Pharmaceutical Asia Pte. Ltd. ;
  • 2.Provides us with general health information {such as information on certain health conditions) as well as information about our products and/or services;
  • 3.Applies for a job with us or for us to consider a candidate employment;
  • 4.Enters into research and development efforts with Santen Pharmaceutical Asia Pte. Ltd. ;
  • 5.Reports an adverse event or communicates product safety information to Santen Pharmaceutical Asia Pte. Ltd. ;
  • 6.Transmits gee-location information to Santen Pharmaceutical Asia Pte. Ltd. via smart phones or other location-aware devices;
  • 7.Uses any online services available at any of Santen Pharmaceutical Asia Pte. Ltd. or its affiliates' or related corporations' websites and/or through other telecommunication channels;
  • 8.Engages Santen Pharmaceutical Asia Pte. Ltd. to facilitate or manage any business transaction{s);
  • 9.Interacts with Santen Pharmaceutical Asia Pte. Ltd. 's officers, employees, authorized agents via telephone calls, mail, in-person meetings, email and any other forms of communication;
  • 10.Conducts research, clinical trials or obtains regulatory approvals or licences for its products devices and services from the relevant authorities in partnership with or on behalf of Santen Pharmaceutical Asia Pte. Ltd. or its affiliates; .
  • 11.Provides Santen Pharmaceutical Asia Pte. Ltd. with Personal Information for identification and verification purposes in connection with any of the services or products that may be supplied to Santen Pharmaceutical Asia Pte. Ltd. or its affiliates or related corporation;
  • 12.Provides Santen Pharmaceutical Asia Pte. Ltd. with Personal Information in order to carry out due diligence or other screening activities in accordance with the law or regulatory requirements or risk management procedures that may have been put in place by Santen Pharmaceutical Asia Pte. Ltd. , including conducting background checks or obtaining of references and/or other information about applicants from previous employers;
  • 13.Requests Santen Pharmaceutical Asia Pte. Ltd. to respond to any enquiries;
  • 14.To disclose to our agents, affiliates or related corporations for the purposes of managing or delivering training programme;
  • 15.Investigating fraud, misconduct, any unlawful action or omissions and whether or not there is any suspicions of the aforementioned;
  • 16.Responding to requests for information from the Government, public agencies, ministries, statutory boards or other similar authorities from time to time;
  • 17.Carrying out market-related or similar research and analysis for Santen Pharmaceutical Asia Pte. Ltd. 's operational strategy and policy planning purposes;
  • 18.Provides Santen Pharmaceutical Asia Pte. Ltd. with Personal Information in order for Santen Pharmaceutical Asia Pte. Ltd. or its affiliates to organize events for healthcare professionals or patients;
  • 19.Provides Santen Pharmaceutical Asia Pte. Ltd. with Personal Information for legal purposes (including but not limited to obtaining external legal advice and dispute resolution proceedings);
  • 20.Consents to Santen Pharmaceutical Asia Pte. Ltd. sending them marketing, advertising, and promotional information, including materials and information on courses held or conduct by or on behalf of Santen Pharmaceutical Asia Pte. Ltd. or related corporations and/or other events via postal mail, email, SMS, fax, voice calls or other forms of communication;
  • 21.Provides Santen Pharmaceutical Asia Pte. Ltd. with Personal Information for any other additional purpose that is consistent with the original purpose for which consent was given; and
  • 22.Provides Santen Pharmaceutical Asia Pte. Ltd. with their Personal Information for any other reasons.

Where personal data is publicly available, we may be able to collect the data from such public sources, including any online presence you may have. On the categories of personal data we collect and process, this would be the data that you or other data subjects provide to us, such as your name, address, email address, telephone number, age, marital status, information issued by government agencies, and other information that may be used to enter into or help perform a contract we have with you, provide you with products and services, communicate with you, or meet any of the purposes set out Clause 4.

Insofar as you disclose personal data when accessing or visiting the Santen Pharmaceutical Asia Pte. Ltd. website, we may process such personal data as well. Further, we may collect and process information that is normally collected as a standard part of your browsing activity. This may include your IP-address, access times, system activity, cookies, device identifier and hardware information, and other log information that is collected when you browse or visit our sites and accounts.

5. Purposes of collection and processing; recipients of personal data

We collect and process personal data for the purposes (i) for which you have provided the data or made ii otherwise available to us or to the public, and to enable us to fully and efficiently achieve those purposes, (ii) as allowed by applicable law, and (iii) those purposes specified in Clause 4 (collectively, the "Purposes").

Recipients of personal data that we collect include persons within Santen Pharmaceutical Asia Pte. Ltd. (including any affiliates or related companies), and third parties to whom we have outsourced or may outsource certain business or operating activities, advisers, suppliers, and service providers, in order to achieve the Purposes. Some of these entities may be outside Singapore, so that transfer of data will be cross-border. We may also disclose information, whether intended to be kept confidential or not, upon lawful request by a governmental authority, in response to a court order, or when required by applicable law. Please see Clause 4 for more information about persons to whom personal data may be transferred or shared.

6. Consent and other lawful criteria for collection and processing
  • 1.Where you have provided us with your personal data through any of the interactions mentioned in Clause 4, in providing or making available the personal data, you agree and consent to our collecting, using, disclosing, sharing and otherwise processing the personal data for the Purposes, and in the manner and under the terms and conditions, in this Policy. This supplements but does not supersede nor replace any other consents you may have previously provided or will provide to us in respect of your personal data, or the existence of a lawful basis or bases for the collection and processing of your personal data.
  • 2.Applicable law allows us to process your personal data in accordance with other criteria or where the data is not covered by the PDPA.
7. Scope and method of collection and processing
  • 1.We utilize standard manual and computerized methods and systems to file, store and process personal data. Collection and processing of personal data will be undertaken in accordance with the principles sat out in this Policy and as required by law.
  • 2.We will store and retain personal data for such period as may be required by applicable law or as may be needed to enable us to fully and efficiently achieve the Purposes.
8. Amendments and supplements

We may amend or update this Policy. You agree to be bound by the prevailing terms of this Policy as updated from time to time, upon the amendment or supplement being published on our website or otherwise advised to you. Please check our website regularly for updated information about, or amendments or supplements to, the Policy.

9. Rights of data subjects

Under the PDPA, data subjects have the following rights:

  • 1.Right to object
    As a data subject, you have the right to indicate your refusal to the collection and processing of your personal data, including processing for direct marketing, automated processing, or profiling. You also have the right to be informed and lo withhold your consent lo further processing in case there are any changes or amendment to information given to you. Once you have notified us of the withholding of your consent, further processing of your personal data will no longer be allowed, unless:

    (i) The processing is required pursuant to a subpoena, lawful order, or as required by law; or
    (ii) The collection and processing is undertaken pursuant to any lawful basis or criteria indicated under Clause 7.2.
  • 2.Right to access
    Upon your request, you may be given access to your personal data that we collect and process, as described in Clause 4. You also have the right to request access to the circumstances relating to the processing and collection of your personal data, insofar as allowed by law.
  • 3.Right to rectification
    You have the right to dispute any inaccuracy or error in your personal data and may request us to immediately correct ii. Upon your request, and after correction has been made, we will inform any recipient of your personal data of its inaccuracy and the subsequent rectification that was made.
  • 4.Right to erasure or blocking
    In the absence of any other legal ground or overriding legitimate interest for the lawful processing of your personal data, or when there is substantial proof that your personal data is incomplete, outdated, false, or has been unlawfully obtained, you may request us to suspend, withdraw, or order the blocking, removal, or destruction of your personal data from our filing system. We may also notify those who have previously received your processed personal data.
  • 5.Right to damages
    You have the right to be indemnified for any damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of your personal data, taking into account any violation of your rights and freedoms as a data subject, as provided by law.
  • 6.Right to data portability
    In case your personal data was processed through electronic means and in a structured and commonly used format, you have the right to obtain a copy of your personal data in such electronic or structured format for your further use, subject to the guidelines of the National Privacy Commission with regard to the exercise of such right.
  • 7.Transmissibility of rights of the data subject
    We wish to advise you that upon the passing of a data subject, or in case of a data subject's incapacity or incapability lo exercise legal rights, the data subject's lawful heirs and assigns may invoke the data subject's rights in place of the data subject.
  • 8.Limitation on rights; manner of exercising
    The rights mentioned under this item are not applicable if personal data are processed only for scientific and statistical research purposes, and without being used as basis for carrying out any activity or taking any decision regarding you as the data subject. Your rights as a data subject are also subject to other limitations provided by law.
    The law requires you to exercise your rights as described in this Policy in a reasonable and non-arbitrary manner, and with regard to rights of other parties.

    All requests, demands or notices which you may make under this Policy or applicable law must be made in writing, and will only be considered made and received if sent in accordance with Clause 13.2.
10. Security Measures

We have taken appropriate security measures to protect your personal data against unauthorized access or unauthorized alteration, disclosure, or destruction. These measures include internal reviews of our data collection, storage, and processing practices, as well as physical security measures to protect your information against unauthorized access. As part of our efforts to ensure your information is protected, we restrict access to personal data to personnel who would need that information to perform their functions.

11. Data breaches

We will comply with the relevant provisions of rules and circulars on handling personal data security breaches, including notification to you or to the National Privacy Commission, where an unauthorized acquisition of sensitive personal information or information that may be used to enable identity fraud has been acquired by an unauthorized person, and is likely to give rise to a real risk of serious harm to the affected data subject. Please note that under applicable law, not all personal data breaches are notifiable.

12. Data Protection Officer

The Data Protection Officer (DPO) is the individual principally responsible for ensuring Santen Pharmaceutical Asia Pte. Ltd. 's compliance with applicable laws and regulations for the protection of data privacy and security. The DPO is responsible for the supervision and enforcement of this Policy, and the relevant contact details are as follows:

Data Protection Officer Email dpo_sg@santen.asia

13. Inquiries; notices
  • 1.For any inquiry related to this Policy, please contact our Data Protection Officer through the contact details indicated above.
  • 2.All requests, demands or notices which a data subject may send or submit to us under this Policy must be in writing, should be addressed to the Data Protection Officer using the contact details above, and will be deemed duly given (i) on the date of delivery if delivered personally, (ii) on the third Business Day following the date of sending if delivered by a nationally recognized next-day courier service and the service has confirmed delivery, or (iii) if given by electronic mail, when such electronic mail is transmitted to the email address specified above and the appropriate confirmation has been received by the sender via email.
Schedule 1 - Definition of Terms
  • 1.

    Definitions

    Whenever used in this Policy, the following terms shall have the respective meanings as set forth below:

    "Business Day'' means any day that Singapore banks are open for business,
    "PDPA" means the Singapore Personal Data Protection Act 2012 and its implementing rules and regulations, as well as the circulars issued by the Personal Data Protection Commission Singapore from time to time.
    "Person" means any natural or juridical person.
    "Personal data" means personal information and sensitive personal information.
    "Personal information" refers to any information, whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information, would directly and certainly identify an individual;
    "Policy" means this data privacy policy as may be amended, modified or supplemented from lime to lime.
    "Processing" refers to any operation or any set of operations performed upon personal data including, but not limited to, the collection, recording, organization, storage, updating, or modification, retrieval, consultation, use, consolidation, blocking, erasure, or destruction of data. Processing may be performed through automated means, or manual processing, if the personal data are contained or are intended to be contained in a filing system.
    "Sensitive personal information" refers to personal information: (1) about an individual's race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations; (2) about an individual's health, education, genetic or sexual life of a person, or to any proceeding for any offense committed or alleged to have been committed by such individual, the disposal of such proceedings, or the sentence of any court in such proceedings; (3) issued by government agencies peculiar to an individual which includes, but is not limited to, social security numbers, previous or current health records, licenses or its denials, suspension or revocation, and tax returns; or (4) specifically established by an executive order or an act of Congress to be kept classified.

  • 2.

    Construction

    Whenever the word, "include," "includes" or "including" are used in this Policy, they shall be deemed to be followed by the words "without limitation".

    The meaning assigned to each term used here will be equally applicable to both the singular and plural forms of such term, and the words denoting any gender shall include all genders.

Schedule 2 - Personal data not covered

This Policy does not apply to the following information:

  • 1. Information processed for the purpose of allowing public access to information that fall within matters of public concern, pertaining to:
    • 1.Information about any individual who is or was an officer or employee of government that relates to his or her position or functions;
    • 2.Information about an individual who is or was performing a service under contract for a government institution, but only insofar as it relates to such service, including his name and the terms of his contract; and
    • 3.Information relating to a benefit of a financial nature conferred on an individual upon the discretion of the government, such as the granting of a license or permit, including the name of the individual and the exact nature of the benefit: Provided, that they do not include benefits given in the course of an ordinary transaction or as a matter of right.
  • 2.Personal information that will be processed for research purpose, intended for a public benefit, subject to the requirements of applicable laws, regulations, or ethical standards; and
  • 3.Information necessary in order to carry out the functions of public authority, in accordance with a constitutionally or statutorily mandated function pertaining to law enforcement or regulatory function, including the performance of the functions of the independent, central monetary authority, subject to restrictions provided by law.