We strongly recommend you contact BMS to report Side Effects (Adverse Events)
Side Effects (Adverse Events) and other reportable events are defined here
Report Side Effects (Adverse Events) or Product Quality Complaints: Medical Information
Bristol Myers Squibb, S.A.U., with registered office at C/ Quintanavides, 15, 28050, Madrid, Spain, and its affiliates and subsidiaries (jointly, the “Company” or “Us”) intend to adequately comply with the applicable data protection requirements.
Liable |
Bristol Myers Squibb, S.A.U. |
Purpose of the processing |
Involve and support participants/caretakers/healthcare professionals in studies before, during and after clinical trials. |
Legitimation |
(i) Need to process data in order to be able to manage and control the relationship with users (ii) Consent (iii) Compliance with the applicable legal obligations |
Recipients |
If necessary, to comply with the legitimate purposes stated above, data shall be transferred to other companies of the Group. |
Rights |
The User has the right to the access, rectification, erasure, objection, portability and restriction of processing of his/her Personal Data through the means described herein. |
1. SCOPE OF APPLICATION
This Privacy Policy and Cookies Policy (“Policy”) provides individuals (“Users”) receiving our services (which are those related to our activities, for the purpose of managing, administering and providing services and accesses to information and/or features provided by BMS through the Site), certain relevant information on the way in which the Company processes their Personal Data. The Company is the controller of the Personal Data.
2. TYPE OF PERSONAL DATA PROCESSED
The following Personal Data may be processed: Name, last name(s), telephone number, country, zip code, profession, email address.
3. PURPOSE OF THE PROCESSED DATA, LEGAL BASIS FOR THE PROCESSING AND PERSONAL DATA COMMUNICATIONS
Data collected by us and how we use them
a) Personal data collected directly from the User
In some areas of this Site, we collect data from the User by directly requesting said data from him/her, so that we may answer requests or give access to areas/content/specific characteristics. The User will always have the option to refuse to provide the information requested, but they may not receive access to specific content, sections or functions.
Below, we explain which data we collect directly from the User, for what purposes and on which basis we process these data for You.
• Contact
If the User contacts us through the information appearing in the “Contact Information” section of our websites, data such as name, telephone number, professional information and email address may be requested. We only process the data provided by You to deal with and answer your queries (Art. 6 (1) b) and f) GDPR).
• Selection Questionnaires
In our Site, we have questionnaires related to your state of health and treatments, in order for You to see if Bristol Myers Squibb Clinical Trials are an option for You. If your answers coincide with a clinical trial, You may have the option to register and send your completed questionnaire to the Healthcare Center where the Clinical Trial is being conducted, where You will be examined and the required measures will be applied.
BMS and its contractual partners may save and use your answers; however, these answers are not related to your personal data until You decide to register to send your data to a clinical testing site. When completing the questionnaire, You must enter your birth year.
• Other Uses of Data
We may use personal data provided by the User on the Site for internal purposes. These purposes include the administration of the Site, data analysis and compliance with our legal obligations, guidelines and procedures. In no event shall BMS have access to your health data.
b) Automatically Collected Personal Data
We automatically collect certain data about the way Users use the Site by placing cookies and reading them from their devices. To obtain detailed information on the use of cookies on our Site, please consult the “Cookies” section.
Legitimation for the processing:
The Company’s legitimation for Personal Data processing includes the processing of data required for (i) the legitimate interests of the Company, including those described above, such as the performance of internal analyses and studies that may improve the quality of the services offered and the establishment, exercise and defense of legal actions; (ii) the compliance with the legal obligations of the Company; (iii) the compliance of the user agreement concluded between the Company and Users in those cases in which the User requests information; and/or (iv) arising from the consent given by the User, who may subsequently withdraw it at any time by contacting the Company at the address mentioned below in the “Contact Information” section, without affecting the legality of the processing based on the consent prior to its withdrawal.
If the User is required to provide Personal Data for any of the aforementioned processing and such details are not provided, they may not make use of or participate in/access the corresponding activity/information.
If the User provides third-party data (such as email address or similar information), it is the responsibility of the User to make sure that the communication of said data and its subsequent processing by the Company is legitimate.
Personal data communications
If necessary, BMS shall share Users’ personal data with its parent company, Bristol Myers Squibb Company, 345 Park Avenue NY 10154, USA (BMS USA), a subsidiary of BMS USA, along with services providers, for the above-mentioned purposes. The service providers are included in one of the following categories: IT (support and maintenance of applications, software infrastructure), who have their headquarters in the United States and India.
Some data receivers are located in countries outside the European Union or the European Economic Area (“third-party countries” without an adequate level of data protection). For these data receivers, BMS has taken the adequate measures to guarantee that any personal data transmitted are properly protected, for example, through EU standard contractual clauses of Binding Corporate Rules. A copy of the aforementioned clauses may be obtained by contacting the Company at the address indicated in the “Contact Information” section.
4. PERSONAL DATA RETENTION
Keep in mind that Bristol Myers Squibb automatically deletes User data a year after consent is given for Bristol Myers Squibb, and the parties with whom BMS works, to save and use their data in order to provide them with related notifications and services.
Keep in mind that the data sent to a Center upon the request of a User (questionnaire) are subject to the privacy policy of the Center and the User must make a request directly to the Center for the removal of his/her data.
Data collected in accordance with paragraph 3) a) through the contact form are stored for the maximum period of one year; after that, User data will be deleted.
Please consult the “Cookies” section in order to obtain information regarding the duration of storage of the data collected under paragraph 3) b).
5. USE OF COOKIES
“Cookies” are small data files stored in your computer or other devices, such as tablets or mobile telephones, by the web pages that You visit. They are widely used on the Internet in order for websites to operate or work more efficiently, as well as to provide information to the websites’ owners.
Most web browsers allow Users to have a certain control over most cookies through the browser configuration options. In this case, however, some pages of this Site or others may not work correctly.
To learn more about cookies, including which cookies are used by a certain website and how to manage and delete them, You can visit the following web pages for general information, which are external to BMS: www.aboutcookies.org o www.allaboutcookies.org.
You may easily modify your preferences on cookies by clicking the TRUSTe icon that You will find on each web page.
6. DATA SECURITY AND INTEGRITY
The Company maintains reasonable security measures to safeguard Personal Data from risks such as their loss, interference, misuse, unauthorized access, disclosure, alteration or destruction. The Company also maintains reasonable procedures to help ensure that such data are reliable for their expected use and that they are precise, complete and up to date.
7. RIGHTS
In accordance with legal provisions on data protection, the User has the right at any time to:
• request information on the data processed by us, as well as a copy of these data (right to access);
• correct incorrect data and demand the removal of incomplete data in consideration of the processing purposes (right to rectification);
• demand the removal of their data for legitimate reasons (right to erasure);
• demand the restriction of processing of their data, if the legal requirements are met (right to the restriction of processing);
• if the legal requirements are met, to receive their data in a structured, commonly used and machine-readable format, and for those data to be transmitted to another controller or, when technical feasible, for them to be transmitted by Bristol Myers Squibb (right to data portability); and
• to not to be subject to a decision based solely on an automated decision-making process, if the legal requirements for this are met. Currently, Bristol Myers Squibb does not participate in automated decision-making processes for the use of the Site.
Furthermore, Users have the right to object to their data processing for reasons deriving from their particular situation, in cases provided for by the law (right to object).
Moreover, You have the right to withdraw your previously given consent, in relation to the registration or the use of our services, but this will not affect the legality of the processing based on the consent given before your withdrawal.
Furthermore, notwithstanding other legal actions, You have the right to submit a complaint to the regulatory authority at any time. Requests must be sent in writing to the address indicated below in the “Contact Information” section.
8. COMMUNICATIONS REQUIRED OR PERMITTED BY LAW
Regardless of any other provision of this Policy, the Company may reveal or process Personal Data in the context of any sale or transaction that involves all or part of the business, or as required or permitted by law for the purposes of any regulatory audit to which the Company may be occasionally subject.
9. Contact Information
Users may ask any questions regarding the processing of their Personal Data by contacting us through the email address of the Company’s Data Protection Officer: EUDPO@bms.com
10. LINKS TO OTHER WEB PAGES
In some cases, links to other web pages are provided for informational purposes for the convenience of the User. The management of these web pages is independent of this page and it is not under the control of the Company. We recommend consulting the data protection policy or the conditions of use of these web pages or any product or service offered through them.
We strongly recommend you contact BMS to report Side Effects (Adverse Events)
Side Effects (Adverse Events) and other reportable events are defined here
Report Side Effects (Adverse Events) or Product Quality Complaints: Medical Information