DATA PRIVACY AND PROTECTION

Under the ICanCare Patient-Centric Mobile Application Program (“Program”), Novartis Corporation (Malaysia) Sdn Bhd (“Novartis”) is solely responsible for the collection and processing of your personal data as Novartis decides why and how it is processed, thereby acting as the “Data User”.

 Purpose of Personal Data Collection & Processing

Caspian Digital Solutions Sdn Bhd (“Caspian”) is the appointed Program Administrator by Novartis to execute Program introductory and enrollment activities (“Purpose”), thereby acting as the “Data Processor”, who shall collect and process your personal data required (such as username, email address and/or password) on behalf of Novartis for the said Purpose.

Anonymization: Caspian will anonymize each identifiable data prior sharing with Novartis for Program monitoring purpose.

Access to your personal data and to whom are they share and/or transfer

Novartis will not sell, share or transfer your personal data to third parties other than authorized third party (including Caspian).

In the course of our activities and for the said Purpose, your personal data can be accessed by, or transferred to authorized third party. The authorized third parties are contractually obliged to protect the confidentiality and security of your personal data, in compliance with Malaysia Personal Data Protection Act 2010 “PDPA”.

Your personal data can also be accessed by or transferred to any national and/or international regulatory, enforcement, public body or court where we are required to do so by applicable law or regulation or at their request.

Technical and organization measure to protect

Novartis has implemented appropriate technical and organizational measures to provide an adequate level of security and confidentiality to your personal data as required under PDPA and contractually bind authorized third party on its obligation to provide similar protection of your personal data in compliance with PDPA. The purpose thereof is to protect it against accidental or unlawful accidental loss, unauthorized disclosure, or access and against other unlawful forms of processing, destruction or alteration.

Retention of your Personal Data

Novartis will instruct authorized third party to only retain your personal data in accordance with legal and regulatory requirements. When the period expires, your personal data will be removed from authorized third-party active systems.

Your data subject rights

You may exercise the following data subject rights or make enquiry about privacy by sending an email to support@icancare.app:

(a) Right to access your personal data processed by Data User and its authorized third party;

(b) Right to correct if you believe that any information relating to you is incorrect, obsolete or incomplete, or request for its updating; and

(c) Right to withdraw consent on processing of your data anytime, without affecting the lawfulness of processing before such withdrawal and subsequent data retention in accordance with applicable local laws.

By clicking the button, you agree to allow your personal data to be collected and processed in accordance with all the terms and conditions set out above.