Sumitomo Pharma America, Inc. Consumer Health Data Privacy Policy

Effective: October 31, 2024

This Consumer Health Data Privacy Policy (“Policy”) describes how Sumitomo Pharma America, Inc. (collectively, “Sumitomo Pharma America”, “we”, “us”, or “our”) collects, uses, and discloses Consumer Health Data, and the rights available to consumers with respect to their Consumer Health Data.

This Policy only applies to “Consumer Health Data” as that term is defined under applicable Consumer Health Data privacy laws that require us to maintain this Policy, such as Washington’s My Health My Data Act and Nevada’s Consumer Health Data Privacy Law. This Policy does not govern health-related data that we or our partners collect or use in connection with clinical trials or other research, or any other health information that is not governed by applicable Consumer Health Data privacy laws.

This Policy supplements the information in our general Privacy and Cookie Notice and only applies to individuals from whom we collect Consumer Health Data in Washington, Nevada, or other states which may in the future require us to provide disclosures specific to Consumer Health Data. If there are any differences between the practices described in our Privacy Notice and what we explain in this Policy relating to your Consumer Health Data, this Policy will control.

This Policy applies to all Sumitomo Pharma America operations as well as websites, mobile applications and digital services that link to or post it.

1. COLLECTION OF CONSUMER HEALTH DATA

Depending on how you interact with us, we may collect different types of Consumer Health Data about you. Examples of the categories of Consumer Health Data we may collect include:

  • Individual health conditions, treatment, diseases, or diagnoses, or testing (including surgeries, health-related procedures, use or purchase of prescribed medications, or other social, psychological, behavioral, and medical interventions);
  • Bodily functions, vital signs, symptoms, or measurements;
  • Reproductive or sexual health information;
  • Biometric data;
  • Genetic data;
  • Precise location information that could reasonably indicate a consumer’s attempt to acquire or receive health services or supplies;
  • Data that identifies a consumer seeking health care services; and
  • We also draw inferences from the information we collect from and about you, such as your preferences, characteristics, attributes, and abilities.
  • Some third parties may collect Consumer Health Data about you over time and across different websites or online services you may visit.

2. PURPOSES FOR PROCESSING CONSUMER HEALTH DATA AND HOW WE USE IT

We may use the Consumer Health Data identified above for the following purposes:

  • Performing the services or providing the goods reasonably expected by an average consumer who requests those goods or services;
  • Ensuring security and integrity to the extent the use of the Consumer Health Data is reasonably necessary and proportionate for these purposes;
  • Preventing, detecting, and investigating security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted Consumer Health Data;
  • Resisting malicious, deceptive, fraudulent, or illegal actions directed at us and prosecuting those responsible for those actions;
  • Ensuring the physical safety of natural persons;
  • Short-term, transient use, including, but not limited to, general advertising shown as part of your current interaction with us; provided that we will not disclose Consumer Health Data to a Third Party and/or build a profile about you or otherwise alter your experience outside the current interaction with us;
  • Performing services on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on our behalf;
  • Undertaking activities to verify or maintain the quality or safety of a product, service, or device that is owned, manufactured by, manufactured for, or controlled by us, and to improve, upgrade, or enhance the product, service or device that is owned, manufactured by, manufactured for, or controlled by us; and
  • Marketing and analytics purposes, including communicating with you and promoting our products and services and analyzing interest in and use of our products and services.

Combining Information:

Where permitted by law, we may combine the information we collect automatically with other information you share with us through this website. Where permitted by law, we may also combine information collected through our website and online resources with Sumitomo Pharma America’s offline records and information provided by third parties. We use this consolidated information to improve our website and online resources, enhance our marketing activities, better design our offerings, and facilitate other business functions.

3. SOURCES OF CONSUMER HEALTH DATA

We Collect Consumer Health Data directly from you, as well as from the following sources:

  • Healthcare providers (including specialty pharmacies);
  • Health insurance companies (health plans) and other payors, payment processors and other financial institutions;
  • Authorized/legal representatives, family members, and caregivers;
  • Consumer reporting agencies and other Third Parties who verify the information you provide;
  • Your computer, mobile devices or other internet connected devices (with your permission or automatically) upon downloading and when you visit or interact with our websites, applications, and online platforms;
  • When you contact or visit us (automatically), such as when we record calls to our call centers;
  • Cookies, web beacons, and similar technologies (automatically) when you visit our websites or Third Party websites;
  • Advertising partners who provide digital marketing and analytics services;
  • Third Parties and Processors who provide website and online security services;
  • Third Parties and Processors who provide benefit verification, program enrollment, and product fulfillment services in connection with our products and services;
  • Third Parties and Processors who help us maintain the accuracy of our data and data aggregators that help us complete and enhance our records;
  • Third Parties and Vendors that provide access to information you make publicly available, such as social media platforms;
  • Third Parties and Processors who provide us with supplemental consumer data or data analytics and market research services, such as data aggregators;
  • Third Parties and Processors who assist with fraud prevention, detection, and mitigation;
  • Third Parties and Processors who facilitate, process, and complete transactions for us, such as resellers, sales agents, and program partners.

4. DISCLOSURE OF CONSUMER HEALTH DATA

We may share the categories of consumer health data described above with the following entities or persons as necessary for the purposes above:

  • Affiliates. We may share the information we collect with our affiliates, including our parent company, our subsidiaries, and other affiliated entities.
  • Service Providers. We may disclose information to our service providers who provide us with various business services, including monitoring and maintaining the website, preparing newsletters and mailings, or with whom we are working to provide you services or information for the purposes described in this Notice.
  • Government agencies. We may disclose Consumer Health Data to law enforcement or other government agencies when we believe doing so is necessary to comply with applicable law or respond to valid legal process.
  • Business Transaction Participants. If we sell all or part of our business, make a sale or transfer of assets, or are otherwise involved in a corporate divestiture, merger, consolidation, acquisition, reorganization, dissolution, sale, or other disposition of all or any portion of the business or assets of, or equity interests in the business (including any affiliate), whether as part of a bankruptcy, liquidation, or similar proceeding, we may transfer your personal information, including Consumer Health Data, to third parties as part of that transaction, including at the negotiation stage.
  • Other third parties. In certain circumstances, it may be necessary to provide data to other third parties, for example, to comply with the law or to protect our rights or those of our customers.

5. YOUR RIGHTS REGARDING CONSUMER HEALTH DATA

If you are covered by an applicable Consumer Health Data privacy law, you may have certain rights with to respect to your Consumer Health Data, such as the rights described below.

  • Right to Know. The right to know if we are collecting, using, or disclosing your Consumer Health Data, to access your Consumer Health Data, or to receive a list of the categories of third parties with whom we have shared your Consumer Health Data.
  • Right to Withdraw Consent. If we are processing your Consumer Health Data based upon consent, the right to withdraw that consent.
  • Right to Delete. The right to request that we delete your Consumer Health Data.

Review & Revision of Consumer Health Data for Nevada Consumers: If you would like to review and/or revise your Consumer Health Data, you may submit a request to us via the methods listed below. We will respond to your requests to exercise your rights in accordance with applicable law, but in any case no later than 45 days after receiving your request. We may extend this period up to 45 days only where doing so is permitted under applicable law.

Please note, these rights are not absolute and, in some cases, we may not be able to respond to your request, such as when a legal exemption applies or if we are not able to verify your identity.

To exercise any of these rights, please contact us at Privacy@us.sumitomo-pharma.com or fill out this form. If you have reviewed your Consumer Health Data and would like to request changes, please contact us at Privacy@us.sumitomo-pharma.com or fill out this form. If we decline to act on your request, you may appeal by emailing us within a reasonable period of time after we send you our decision. Please attach a copy of or otherwise specifically reference our decision on your data subject request, so that we may adequately address your appeal. We will respond to your appeal in accordance with applicable law. If your appeal is denied, you may contact the relevant government authority in your state. For Washington residents, the Washington State Attorney General may be contacted at www.atg.wa.gov/file-complaint. For Nevada residents, the Nevada State Attorney General may be contacted at https://forms.office.com/pages/responsepage.aspx?id=5kCj5J64aE6OqhVE0nA5gCJ94DRc5JVMolaLrIFlUBlUMUk1Tk1BSDFRQk80WDY3Szg5NUlYUUxGVC4u.

6. CHANGES TO THIS POLICY

We reserve the right, at any time, to modify this Policy. If we make material changes, we will update the “Last Updated” date at the top of this Policy to indicate the effective date. We will notify you before making any changes to our privacy practices with respect to your Consumer Health Data by posting an updated notice on this page.

7. CONTACTING US

If you have questions about this Consumer Health Data Privacy Policy, our data collection practices, or your rights, please complete this form, or write to:

Sumitomo Pharma America, Inc.
Attn: Data Protection Office
84 Waterford Drive
Marlboro, MA 01752
or
send us an email at: Privacy@us.sumitomo-pharma.com