Privacy policy

How does this privacy policy define "personal data"?

The term "personal data" as used in this Privacy Policy applies to all information relating to an identified or identifiable person.

Which personal data are processed and how are they collected?

There are the following options or methods that are used to collect the following personal data:

  • Data transmitted by you: personal and other data are collected by entering them in myDialog, for example via forms, data fields or means of communication. In particular, such information includes contact information (for example, name, address, email address, telephone number, authentication characteristics), date of birth, job references, hobbies, interests, communications and health data.
  • Patient data provided by the healthcare professional: physician, the treating medical and nursing staff or other persons in the health sector ("medical specialist") transmit personal data of the patients via myDialog. In particular, such data include contact details (for example, name, address, email address), date of birth and health data, such as diagnosis, treatment, medication.
  • Data collected from public data sources or data sources of third parties: personal data about the medical professional is also collected via websites, public information sources or information sources of third parties in order to verify and supplement their identity and professional references.
  • Data collected from your computer or via other electronic devices: on our behalf, third parties collect data about your computer or other electronic devices when you use myDialog. These data may include your Internet Protocol (IP) address, the name of your domain, browser type, date and time of your request, and information provided through tracking technologies such as cookies and single pixel tags. If you use a mobile device to access myDialog, information about your device, such as device ID and device type, as well as usage information about your device and your use of our websites and other mobile resources may also be collected.
    MSD does not have access to your personal data.

If you participate in a study (e.g. Swiss IBD Cohort or B-IBD Cohort), MSD can forward data that you enter monthly via iBDialog to the institution conducting the study. This data can also be personal data.

For which purpose will your personal data be processed?

MSD processes personal data to be able to provide myDialog. In particular, the data are processed for the purpose of information exchange between the patient and the attending physician. Kauz Informatik AG processes your personal data with regard to the surveys conducted by MSD at regular intervals on the user-friendliness of myDialog. If you participate in a study, your personal data may also be processed for the purpose of exchanging information between you and the organising institution.

Only personal data of healthcare professionals submitted upon registration as a healthcare professional may be viewed by MSD to verify the identity of the healthcare professional. Third parties may process personal data on our behalf so that you can register with myDialog and we can tailor this to your needs. These third parties can also use personal data to check access to myDialog and security of the data and to increase the functionality of myDialog. MSD has no access to the personal data of patients and only access to the personal data of healthcare professionals as part of the identity verification process at registration.

What is the legal basis for processing your data?

MSD processes your data on the basis of your consent or to be able to fulfil its contractual and legal obligations in connection with myDialog.

Where are your personal data stored?

Your personal data are stored exclusively in the EU. You yourself have access to your personal data from Switzerland or from abroad, so that you can decide yourself where you wish to process your data. The medical professional is hereby contractually prohibited from processing the data outside Switzerland, in particular from accessing the data from abroad.

Do you have access to your personal data?

As a patient, you have access to the personal data that you or the healthcare professional enter. Access ends when you or the healthcare professional delete this information or when your access is deleted or blocked.

Do the healthcare professionals have access to your personal data?

The healthcare professional has access to the patients' personal data. If the medical specialist shares the patient data with other specialists of the same institution in myDialog, these medical specialists also have access to the personal data of the patients.

Does MSD have access to your personal data?

MSD has no access to unencrypted personal data of patients. MSD only has access to patients' personal data after these have been encrypted and no longer allow any conclusions as to your person. Personal data of healthcare professionals entered by the healthcare professional during registration may be accessed by MSD to verify the identity of the healthcare professional.

Do MSD contract processors have access to your personal data?

For the operation of myDialog, MSD contract processors have access to your personal data only to the extent that you have granted permission to process personal data, provided that these contract processors have concluded contracts and confidentiality agreements with us which protect your personal data in accordance with the latest technical standards. These contract processors may be domiciled in Switzerland, the European Union or elsewhere abroad, even in countries without adequate data protection legislation.

Do third parties have access to your personal data?

App Stores
When you download the App from App Stores, the third party providers may process your personal data. In particular, the App Store providers include Apple Inc. One Apple Park Way, Cupertino, California, USA, 95014 and Google Payments, 1600 Amphitheatre Parkway, Mountain View, CA 94043. MSD has no knowledge of the data you transmit to such providers or of their use by the providers of the App Stores. The providers of App Stores have no access to the exchange of information between the medical professionals and the patients. Further information can be found in the privacy policy of the providers.

Google Analytics
Our website uses functions of the web analysis service Google Analytics. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Analytics uses cookies. Google evaluates the use of our website to compile reports on website activity and to provide MSD with other services relating to website activity and Internet usage. The information generated by the cookie about your use of our website will generally be transmitted to and stored by Google on a server in the United States. Google complies with the data protection provisions of the "Swiss-U.S. Privacy Shield" agreement. We use Google Analytics with an IP anonymization feature on our website. This means that your IP address is shortened by Google before being transmitted to the USA. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. You may refuse the use of cookies by selecting the appropriate settings on your
browser, however please note that if you do this you may not be able to use the full functionality of this website. Google Analytics has no access to the exchange of information between the medical professionals and the patients. For more information, please see Google's privacy policy.

Kauz Informatics AG
Kauz Informatik AG, Luzernstrasse 18, 6275 CH-Ballwil, processes your personal data for the surveys on the user-friendliness of myDialog conducted by MSD at regular intervals.

If you participate in a study (e.g. Swiss IBD Cohort or B-IBD Cohort), the institution conducting the study may process your personal data.

How does MSD protect your personal data?

MSD has implemented the latest technical standards to protect personal data from unauthorized access, disclosure, alteration or deletion. You are responsible for the protection of your own copies, data, authentication characteristics, etc.

How does MSD protect the data of children?

In cases where personal information is collected from children under the age of 16, we require parental consent. If the healthcare professional processes personal data of children under the age of 16 on the basis of false information, he/she is obliged to have this data deleted by sending an email to MSD at the address below.

How can you correct your personal data or request the limitation of processing of your personal data or its deletion or request a copy of the data?

To correct, complete and update your personal data, to request limitation of processing or its cancellation or a copy of the data, you can contact us at the address below.

How can you object to the processing of your personal data?

If the processing of data is not required by law or if no other legal justification exists, you have the right to object to the processing of your personal data. If these requirements are met, we will delete your personal data within a reasonable period of time. If you wish to object, you can contact us at the address below.

How long does MSD store your personal data?

As a rule, we process personal data for as long as is necessary for the specific purpose, but for no longer than 10 years. In some cases, we may be required to retain information for an extended period of time due to laws or regulations which apply to our business, for example, applicable statutes of limitations or other necessary business purposes. Where possible, we will attempt to anonymize the information or remove unnecessary identifiers that we need to retain beyond the original retention period.

What is the MSD address for questions regarding data protection?

If you have any questions about this Privacy Policy or MSD's data collection, use and disclosure policies, please contact us at the following address: MSD Merck Sharp & Dohme AG, Werftestrasse 4, 6005 Lucerne; email: msd_privacy_office@msd.com.
When you contact us, we ask you to quote "myDialog", the data provided by you and sufficient information to allow us to identify you. We will make reasonable efforts to respond to your requests, questions or suggestions regarding the use of your personal data within 10-20 days.

How will you know if MSD has updated this Privacy Policy?

MSD may periodically update this privacy policy. If we decide to change this provision, we will announce the changes made via myDialog.

MyPH Platform & App: CARD-1256407-0001, Date: July 2018; iBDialog Platform & App: GAST-1213352-0015 November 2017
© MSD Merck Sharp & Dohme AG, Lucerne, Switzerland. All rights reserved.