Privacy Notice

1. Preamble

This privacy notice is addressed to all visitors and users of our websites and apps (“user” or “you”) of the Merck Group (“Merck”, “us”).

This privacy policy describes how Merck will use the personal data of the users within the scope of the operation of our websites and/or apps (“services”). “Personal Data” in this document means all information that relates to a natural person and with which this person can be directly or indirectly identified.

Should you have questions or queries regarding the processing of your personal data by Merck, please feel free to contact our Data Protection Officer via dataprivacy@merckgroup.com or the other contact details provided below.

2. General Information

This section informs you who is the controller of the processing of your personal data, how you may contact the controller and which rights you have as a data subject in this context.

2.1. Controller

The data controller means the person who determines the purposes and means of the processing of your personal data. For the processing activities described of in this privacy notice, the controller is

Merck (Schweiz) AG
Chamerstrasse 174
CH-6300 Zug
info@merck.ch
+41 (0)41 729 22 22

2.2. Data Protection Officer

Merck has appointed a Data Protection Officer. You may reach him/her as follows:

dataprivacy@merckgroup.com

3. The Processing Activities in Detail

This section explains the different data processing activities in which Merck processes your personal data for the operation of our services and the provision of information and functionalities.

In general, you are neither contractually nor statutorily obliged to provide your personal data for the below purposes, however your decision to not provide your data may lead to negative consequences, such as reduced features and functionalities and/or, in rare cases, the impossibility to use our information and services offered in this context.

3.1. Operation of our Services

We process your personal data for the purpose of the operation of our services. Whenever you access our services, you automatically transfer personal data to our servers for technical reasons.

This processing activity may include the following data categories:

  • Your IP address;
  • Identifier (manufacturer, version, type of web browser, operating system);
  • Language settings of your web browser;
  • The time of your visit and visited subpages of our website;
  • Your referrer URL (i.e. the URL of the page from which you visit us);
  • The data volume accrued during your visit to our website;
  • Access status (file transferred, file not found, etc.); and
  • Name of the provider of your internet access.

The data processing is based on our legitimate business interests. We process these data for the purpose of presenting our services and to ensure its technical stability and security (e.g. to prevent hacker attacks).

Your data is regularly deleted after a period of seven days, beginning from your use of our service.

No automated decision-making or profiling takes place.

3.2. Contact Forms

We process your personal data to operate the contact form we provide in our service. This enables you to contact us, and e.g. ask for additional information or issue other service requests.
Your personal data will only be processed for the purpose of responding to your inquiry.

This processing activity may include the following data categories:

  • The contact information you provided to us (such as your name and email address); and
  • Other personal information that you include in your request.

The processing is based on our legitimate business interests. It serves our and your legitimate interest in answering your inquiry in a quick and competent manner.

Your personal data will be deleted after six months from the date of collection.

No automated decision-making or profiling takes place.

3.3. Newsletter

We process your personal data if you subscribed to our email newsletter. If you would like to receive our newsletter, you may enter your email address in our registration form and click the “Submit” button. You will then receive an email from us to your email address. You may complete the registration and thus verify your email address for sending newsletters by clicking on the confirmation link in this email.

This processing activity may include the following data categories: The information you provided to subscribe, such as your name, email address and personal/professional interests.

The processing is based on your explicit consent you provided to us in the course of the subscription process.

Your personal data will be deleted when you withdraw your consent, e.g. by clicking on the unsubscribe button which is included in any of our newsletters.

No automated decision-making or profiling takes place.

3.4. Chatbots

You can use chatbots on our website to communicate your concerns to us. Chatbots are programs that, in a joint chat with you, classify your concerns with the help of artificial intelligence in order to forward them to our responsible employees and help you find your way around our website. The personal data provided during these chats will only be processed for the purpose of responding to your request.

This processing activity may include the following data categories: The information you provided within the chat, such as your name, email address and personal/professional interests. Please do not enter any additional unnecessary personal data if it can be avoided.

The processing is based on our (and your) legitimate business interest in the prompt and competent response to your requests.

Your personal data will be deleted within 24 hours, counting from your transmission of your request.

No automated decision-making or profiling takes place.

3.5. Google Maps

We process your personal data to display maps, a service provided by Google LLC.

This processing activity may include the following data categories which will be transmitted to Google LLC in the United States of America:

  • The technical data as described in Section 3.1;
  • Your location;
  • The content you access (e.g. places); and
  • The frequency of these accesses.

The processing is based on our (and your) legitimate business interest to guide you to our premises and facilitate your route planning.

The use of the service is not possible without your data, and these are automatically provided when you open a sub-page on which Google Maps is integrated. We process no further personal data than those specified in Section 3.1. Information on data processing by Google can be found in Google’s privacy policy under the following link: https://policies.google.com/privacy?hl=en.

We do not conduct automated decision-making or profiling in this context.

3.6. Social Bookmarks

We use social media plugins from various social networks (e.g., from YouTube, LinkedIn, Facebook, Twitter) on our services. Social bookmarks are internet bookmarks which enables the users of such services to collect links and news messages. With the help of these plugins you can share content or recommend products. We integrated such bookmarks as links only. That means that they just link you to corresponding services without automatically processing your personal data. If you decide to click on a social bookmark (meaning the embedded graphic), you will be directed to the page of the respective social media network. Please refer to the respective provider’s privacy policy to learn how your personal data are handled when you decide to visit their services.

3.7. Cookies

Cookies improve the user experience on our services because they allow, e.g., the system to recognize returning visitors. The term “cookies” in this privacy notice refers to cookies and similar technologies. The term “computer” in this privacy notice refers to computers, smartphones and all other devices with internet access. Cookies are small, usually randomly coded text files that are sent to your computer and stored there. These cookies allow your browser to track certain information that may be retrieved and used by internet servers at a later stage. Merck uses cookies and similar technologies on its services for several reasons, for example:

  • Websites load faster;
  • Websites may be browsed faster;
  • Your settings, such as language and time zone, may be saved;
  • Security on websites is improved since your identity may be verified; and
  • Your log-in to secured websites is facilitated.

We included the following three categories of cookies on our services:

3.7.1. Necessary Cookies
These cookies are necessary to safeguard the functionalities of our services and for the website to operate. Cookies are set, in particular, in response to your actions and depend on your specific service requests (e.g. setting your privacy preferences, filling out forms, or logging in). More specifically, we set the following cookies:

  • moove_gdpr_popup: This cookie is set by our cookie compliance solution. It stores information about the categories of cookies which are used on our services and whether visitors have granted or revoked their consent per each cookie category. This allows us to avoid setting cookies on your computer if you did not grant your consent. The cookie is usually deleted within one year.
  • SERVERID: The ServerID cookie remembers which server should handle the user’s requests to improve the server time, it expires at the end of each session.
  • JSESSIONID: This cookie stores your current session ID to recognize you and remember your preferences. It expires at the end of each session.
  • cfduid: The cookie is set by the CloudFlare service to identify trusted web traffic. It does not correspond to any user ID in the web application.

The processing is based on our legitimate business interest to be able to provide our basic webservices in a secure and useful manner. Our website cannot function without these cookies and they can only be disabled by changing your browser preferences.

No automated decision-making or profiling takes place.

3.7.2. Functional Cookies
These cookies enable the provision of advanced functionalities and are used for personalization. The cookies are set in particular in response to your actions and depend on your specific service requests (e.g. setting the language). More specifically, we set the following cookies:

  • wp-wpml_current_language: This cookie stores the ISO country code of your (detected) country in order to display information related to your location (e.g. automatic language selection). It expires after two years or upon the withdrawal of your consent.
  • cookiepopup: This cookie hides the “cookie” notification when you have closed this notification. It expires after two years or upon the withdrawal of your consent.

The processing is based on your explicit consent you provided to us in the course of the subscription process. You either grant your consent by accepting all cookies in our cookie banner or by activating the cookie type you have selected. Your consent is voluntary, and you may revoke it at any time with effect for the future. You can revoke your consent by reopening our Cookie Center and deactivating the cookie type. If you do not grant your consent or revoke it, this will not result in any disadvantages for you. However, without your consent, the functions explained above will not be available to you.

No automated decision-making or profiling takes place.

3.7.3. Targeting Cookies
These cookies may be set to learn more about your interests and show you relevant ads on other websites. These cookies work by uniquely identifying your browser and device. By integrating these cookies, we aim to learn more about your interests and your surfing behavior and to be able to place our advertising in a targeted manner. More specifically, we set the following cookies:

  • IDE: This cookie contains a randomly generated user ID. This ID allows Google LLC to recognize you on multiple websites and provide personalized ads. It expires after one year or upon the withdrawal of your consent.
  • gid: This cookie contains a randomly generated user ID. This ID allows Google Analytics (Google LLC) to recognize returning users to this website and merges data from previous visits. It expires after one day or upon the withdrawal of your consent.
  • 9553315_u: This cookie is used for profile tracking and stores a unique identifier for the viewer. It expires after 360 days or upon the withdrawal of your consent.
  • _gat_UA-53025678-1: This is a sample cookie set by Google Analytics (Google LLC), where the sample element contains a unique identity number of the account or website it refers to. It is a variant of the _gat cookie, which is used to limit the amount of data recorded by Google LLC on high-traffic websites. It expires after a few seconds or upon the withdrawal of your consent.
  • _gat: This cookie is linked to Google Universal Analytics (Google LLC). It is used to throttle the request rate and limit data collection on high-volume websites. This cookie expires after 10 minutes or upon the withdrawal of your consent.
  • uuid: This is a session cookie that stores an anonymous identifier for the visitor. The cookie is used by Google Analytics (Google LLC) to make tracking more accurate. This cookie expires after 120 days or upon the withdrawal of your consent.
  • ga: This cookie is associated with Google Universal Analytics (Google LLC) – an update to Google LLC’s more commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a customer identifier. It is included in every page request on a website and is used to calculate visitor, session and campaign data for website analytics reports. By default, it is set to expire after 2 years or upon the withdrawal of your consent.
  • 9553315_p: This Cookie is used for profile tracking and stores the properties the viewer has submitted via collectors. It expires after 360 days or upon the withdrawal of your consent.
  • visual_swf_referer: This is a session cookie used for referral traffic in Analytics (Google LLC). This cookie stores the address of the website that referred traffic to the video player. It expires at the end of the session or upon the withdrawal of your consent.

The processing is based on your explicit consent you provided to us in the course of the subscription process. You either grant your consent by accepting all cookies in our cookie banner or by activating the cookie type you have selected. Your consent is voluntary, and you may revoke it at any time with effect for the future. You can revoke your consent by reopening our Cookie Center and deactivating the cookie type. If you do not grant your consent or revoke it, this will not result in any disadvantages for you. However, without your consent, the functions explained above will not be available to you.

Please note that the use of Google Analytics has been extended by the plug-in “AnonymizeIP “, to ensure an anonymized collection of your IP address, so that we cannot relate your data to your person. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.

3.7.4. Management and Deletion of Cookies
Some computer browsers automatically accept all cookies. In this case, you may not see the Cookie Center which allows you to manage your cookies individually. However, you can change your browser settings to block all cookies. You may also be able to configure your browser settings so that only certain types of cookies are blocked or so that you are notified as soon as a new cookie is to be stored on your computer. In this case, you can accept or reject cookies individually. If this function is available to you, you will find more detailed explanations in the help function of your browser. There you will also find information on how to delete all or certain cookies for which you have given us your consent. For more information on managing and deleting cookies for popular browsers, please see the following links: Google Chrome, Mozilla Firefox, Microsoft Internet Explorer, Microsoft Edge, Apple Safari.

4. Data Transfers

We transfer your personal data as follows.

4.1. Merck Group

To our worldwide affiliates, to the extent that this is permissible within the framework of the purposes and legal bases stated under 3. In these cases, our group companies will use the personal data for the same purposes and under the same conditions as described in this privacy notice (e.g., answering your inquiry about a product that falls within the area of expertise of a foreign Merck affiliate). A list of our affiliated group companies and their contact details can be found here. If and to the extent we transfer your personal data in this context to a country outside the EU or the EEA and to which no adequacy decision of the European Commission exists, we safeguard an adequate level of data protection by entering into the EU standard contractual clauses with such affiliate. You may obtain these EU standard contractual clauses here.

4.2. Service Provider

We may also engage service providers (data processors) within (e.g. shared service centers) or outside the Merck Group (e.g. hosting providers, support service providers) to process personal data in accordance with our instructions. In these cases, we retain control over and remain fully responsible for your personal data. We will take all reasonable safeguards required by applicable law to ensure the integrity and security of your personal data when engaging such service providers and will, should these service providers process your personal data in a country outside the EU or the EEA, safeguard an adequate level of data protection by entering into the EU standard contractual clauses with such service provider. You may obtain these EU standard contractual clauses here.

4.3. Public Authorities

In certain cases, we are required by law to transfer data to a requesting public authority.

Upon submission of a court order, we may be obliged by national Copyright Acts to provide owners of copyright and ancillary copyrights with information about customers who are alleged to have infringed copyright laws. In these cases, we may be obliged to transfer your personal data, in particular your user ID of an IP address allocated at the time requested and, if known, your name and address.

In other respects, personal data will only be transferred to state institutions and public authorities within the framework of mandatory national legal provisions or if disclosure is necessary in the event of attacks on the network infrastructure for legal or criminal prosecution.

5. Your Data Protection Rights

Regarding the data processing in the European Union, you have the following data protection rights:

  • Right of access: You have the right to obtain information on the processing of your personal data and to receive a copy these data.
  • Right to rectification: You have the right to ask us to correct or complete your personal data to the extent they prove to be wrong and/or incomplete.
  • Right to erasure: Under certain circumstances, you have the right to ask us to delete your personal data.
  • Right to restriction of processing: You may also have the right to ask us to limit the processing of your personal data.
  • Right to data portability: You have the right to receive your personal data in a structured, common and machine-readable format and request that these data are transferred to another data controller.
  • Right to object: You have the right to object to the processing of your personal data by us, in particular if the processing of your personal data is based on (i) the necessity of the performance of a task in the public interest, or (ii) legitimate interests. We will then stop the processing of your personal data unless we remain legally authorized to do so.
  • Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a supervisory authority against the processing of your personal data if you believe that the processing of your personal data violates data protection regulations.