This Privacy Notice applies to the entities that comprise Roche Diagnostics Solutions and Roche Information Solutions, including Roche Molecular Systems, Inc., Roche Sequencing Solutions, Inc., Ventana Medical Systems, Inc., and GenMark Diagnostics, Inc., (“Roche”) to the extent applicable with respect to your specific activities and interactions with the respective applicable Roche entity.
Last Updated June 2024
Purpose and Reach | Information Collected | Consumer Health Data | Marketing, Cookies, and Tracking | Third Parties | Your Rights Regarding Your Personal Data | Safeguarding Information | Personal Data Retention | Special Note to Patients | Changes to This Privacy Notice | Contact Us
Roche (“Roche,” “we,” “our,” or “us”) values your privacy and the protection of your Personal Data. This Privacy Notice (“Notice”) explains how we collect, store, use, share, transfer, delete, and process information collected from or about you known as Personal Data (defined further below in this Notice).
___________________________________________________________________________________
This Notice describes the types of Personal Data that Roche may collect or process from United States (“US”) residents, how we may use and disclose that Personal Data, and how you may exercise any rights you may have regarding our processing of your Personal Data.
This Notice applies to Personal Data collected or processed by us from or about US residents:
Roche may provide you with a different privacy notice in certain specific situations, in which case that privacy notice or policy will apply to the Personal Data collected or processed in that specific situation, rather than this one. For example, if you are a participant in a clinical study, clinical trial, or other regulated health-related research, you should receive a separate privacy notice regarding the Personal Data we process for those purposes. That privacy notice—and not this Notice— governs our processing of such Personal Data. If you provide us with Personal Data of anyone other than yourself (such as a patient or family member), please note that you are responsible for complying with all applicable privacy and data protection laws prior to providing that information to Roche (including obtaining consent, if required).
Please review this Notice carefully. To the extent permitted by applicable law, by providing us your Personal Data or otherwise interacting with us, you are agreeing to this Notice.
___________________________________________________________________________________
“Personal Data” is any information—as electronically or otherwise recorded—that can be used to identify a person or that we can link to or associate with a specific individual.
Personal Data may include information considered sensitive in some jurisdictions, such as biometric information, genetic information, health information, financial account information, specific geolocation, ethnic or racial origin, information concerning your sex life or your sexual orientation, social security number, driver’s license, state identification card, passport number, and other similar information. Data that could be considered Sensitive Personal Data is highlighted with an asterisk (*) in the chart below.
We will process any Personal Data we collect in accordance with applicable law and as described in this Notice (unless, as explained above, a separate policy or notice governs). In some circumstances, if you do not provide us with your Personal Data, certain Products and Services may be unavailable to you.
The chart below identifies the categories of Personal Data that we collect and use and the types of data elements associated with each.
Category and Sources of Personal Data |
Representative Data Elements |
---|---|
Contact Information |
Data elements in this category may include:
|
Physical Characteristics, Demographics, or Description |
Data elements in this category include:
|
Commercial and Financial Information |
Data elements in this category may include:
|
Transaction and Interaction Information
|
Data elements in this category include:
|
Inferred and Derived Information |
Data elements in this category include:
|
Internet and Online/ Electronic Technical Information |
Data elements in this category include:
|
Audio Visual Information
|
Data elements in this category include:
|
Health Information |
Data elements in this category include:
|
Electronic and Sensor Data |
Data elements in this category include:
|
Geolocation Data |
Data elements in this category include:
|
Children’s Data*
|
Data elements in this category include:
|
Compliance Data |
Data elements in this category include:
|
Professional and Educational Information |
Data elements in this category include:
|
Sensitive Personal Data
(Sensitive Personal Data is marked with an asterisk (*) throughout this chart.) |
Some of the Personal Data we collect may be considered “Sensitive Personal Data” under certain data protection laws. Sensitive Personal Data, may include biometric information, genetic information, health information, financial account information, specific geolocation, ethnic or racial origin, information concerning your sex life or your sexual orientation, social security number, driver’s license, state identification card, passport number. You may make choices about your Sensitive Personal Data as set forth in “Your Rights Regarding Your Personal Data” section, below. For more information about how we collect, disclose, and share Sensitive Personal Data, please see the chart below that represents your relationship with Roche. |
Written Signature
|
Data elements in this category include:
|
The types of Personal Data we collect and disclose depend on your relationship with Roche. Not all of the categories listed in the following charts may apply to you. If the nature of your relationship with Roche changes, additional categories of Personal Data may also apply.
CONSUMERS (INCLUDING THOSE INTERESTED IN OUR PRODUCTS, SERVICES, OR CLINICAL TRIALS), PATIENTS, CAREGIVERS, FACILITIES VISITORS. The following table provides detail for those who interact with us as (i) consumers – those showing interest in our products and/or services, (ii) individuals interested in participating in clinical trials, (iii) patients using our products/services and their caregivers, and (iv) facility visitors, with respect to the category of Personal Data collected, the source of that information, the purposes for collection and sharing/disclosure, and the categories of third parties to whom the category of Personal Data is shared.
Category and Sources of Personal Data |
Purpose for Collecting and Sharing and Disclosing the Personal Data |
Categories of Third Parties to whom this type of Personal Data is Shared or Disclosed for a Business Purpose |
---|---|---|
Contact Information We collect this type of information from:
|
We use and disclose this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Physical Characteristics, Demographics, or Description We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Commercial, Financial, and Insurance Information We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Transaction and Interaction Information We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Inferred and Derived Information
|
We combine inferred data with other relationship information and use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Internet and Online/ Electronic Technical Information We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Audio Visual Information We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Health Information We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Electronic and Sensor Data We collect this type of information automatically when you use our internet-enabled products such as mobile apps and connected devices from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Geolocation Data We collect this type of information automatically, when enabled on your mobile device and computer, when you visit or interact with our websites, applications, and online platforms. |
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Children’s Data We collect this type of information from children when they use our apps and from parents or guardians. This is done in accordance with applicable laws. |
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Compliance Data We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Written Signature We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
CALIFORNIA PROFESSIONALS. The following table provides detail for residents of California who interact with us as (i) health care providers and their staff, (ii) clinical investigators and their staff, (iii) employees of companies with whom we conduct business, including employees of service providers, with respect to the category of Personal Data collected, the source of that information, the purposes for collection and sharing/disclosure, and the categories of third parties to whom the category of Personal Data is shared.
Category and Sources of Personal Data |
Purpose for Collecting and Sharing and Disclosing the PI |
Categories of Third Parties to whom this type of Personal Data is Shared or Disclosed for a Business Purpose |
---|---|---|
Contact Information We collect this type of information from:
|
We use and disclose this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Physical Characteristics, Demographics, or Description We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Commercial, Financial, and Insurance Information We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Transaction and Interaction Information We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Inferred and Derived Information
|
We combine inferred data with other relationship information and use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Internet and Online/ Electronic Technical Information We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Audio Visual Information We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Electronic and Sensor Data We collect this type of information automatically when you use our internet-enabled products such as mobile apps and connected devices from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Geolocation Data We collect this type of information automatically, when enabled on your mobile device and computer, when you visit or interact with our websites, applications, and online platforms. |
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Professional and Education Data
We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Compliance Data We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Written Signature We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
CALIFORNIA JOB APPLICANTS. The following table provides detail for residents of California who interact with us applicants for jobs, with respect to the category of Personal Data collected, the source of that information, the purposes for collection and sharing/disclosure, and the categories of third parties to whom the category of Personal Data is shared.
Category and Sources of Personal Data |
Purpose for Collecting and Sharing and Disclosing the PI |
Categories of Third Parties to whom this type of Personal Data is Shared or Disclosed for a Business Purpose |
---|---|---|
Contact Information We collect this type of information from:
|
We use and disclose this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Physical Characteristics, Demographics, or Description We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Inferred and Derived Information
|
We combine inferred data with other relationship information and use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Internet and Online/ Electronic Technical Information We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Audio Visual Information We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Professional and Education Data
We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Written Signature We collect this type of information from:
|
We use this type of information:
|
We may disclose this type of information to our Affiliates and Service Providers and to:
|
Mergers and Acquisitions. In addition to the uses set forth above, in certain circumstances, we will use and disclose your Personal Data to facilitate a merger, consolidation, transfer of control or other corporate reorganization in which Roche participates, or pursuant to a financial arrangement undertaken by Roche and your Personal Data will be disclosed to the buyer, assignee, or transferee.
Data Retention. We will retain your Personal Data for as long as needed or permitted to fulfill the purpose(s) for which it was collected or obtained, and as outlined in this Privacy Notice. The criteria used to determine our retention periods include: (i) the length of time we have an ongoing relationship with you; (ii) whether there is a legal obligation to which we are subject that affects the Personal Data; and (iii) whether retention is determined to be necessary or advisable for Roche due to applicable statutes of limitations, litigation, or other legal or regulatory obligations. Roche takes reasonable steps to dispose of Personal Data upon the expiration of retention periods taking into consideration these litigation, legal, or regulatory obligations.
De-Identification. Roche may de-identify your Personal Data, which means it will remove certain data from your Personal Data, such as Contact Information, such that the resulting data would not be able to identify you or anyone else as the subject of the data. The de-identified data will no longer be Personal Data and may no longer be subject to data protection laws. We will not attempt to re-identify you or anyone else from this de-identified data and if we disclose it to third parties, we will require that they commit to not attempting to re-identify you or anyone else from the de-identified data. We will use de-identified data for our business purposes.
___________________________________________________________________________________
The law of the state in which you reside or in which your Personal Data is collected may make specific requirements in connection with Personal Data that is linked or is reasonably capable of being linked to you and that identifies your past, present, or future physical or mental health status (“Consumer Health Data”). Please note that the collection of consumer health data subject to the Washington State My Health My Data Act (the “MHMDA”) is addressed in the separate Washington Consumer Health Data Privacy Policy.
To the extent your Personal Data constitutes “Consumer Health Data,” the categories of Consumer Health Data being collected; the manner in which it will be used; the categories of sources from which it is collected; the categories of third parties and affiliates with whom it is being shared; the purposes of collecting, using and sharing it; and the manner in which it will be processed are all provided in the “Information Collected” section of this Notice (primarily as “Health Information”). Additional information about RDS/RIS’s activities can be found in the “Marketing, Cookies & Tracking” and “Third Parties” sections of this Notice.
To the extent that the state in which you live requires us to provide certain rights to you in connection with your Consumer Health Data, we will provide the following rights to you based on your state’s law:
To request our confirmation that we are collecting, sharing, or selling your Consumer Health Data;
To request to review and to make changes to any of your Consumer Health Data;
To request that we delete your Consumer Health Data;
To request a list of all third parties with whom we have shared or sold your Consumer Health Data;
To request that we stop collecting, sharing, or selling your Consumer Health Data;
To exercise any of these rights, follow the procedure explained in the “Your Rights Regarding Your Personal Data” section of this Notice.
___________________________________________________________________________________
To the extent permitted by applicable law, including in accordance with your consent where required by applicable law, we may engage in the following activities:
On certain of our websites, we use Google Analytics, to help us understand how users engage with this and other of our websites. Google Analytics may track your activity on our sites (i.e., the pages you have seen and the links you have clicked on) and helps us measure how you interact with the content that we provide. This information is used to compile reports and to help us improve the sites. The reports we receive disclose website trends without identifying individual visitors. You can learn about Google’s practices by going to www.google.com/policies/privacy/partners/, and exercise the opt-out provided by Google by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout or clicking on the "Your Privacy Choices" link at bottom of our website.
Certain web browsers and other programs may transmit “opt-out” signals, also called a Global Privacy Control (or GPC) signal (we refer to these as “GPC Signals”), to websites with which the browser communicates. In most cases you will need to change your web browser’s settings or add an application to your web browser to enable your browser to send a GPC Signal. Roche’s websites will recognize GPC Signals for website users differently, based on the location of the user when they access our websites. For users that access our websites from US states that have laws requiring recognition of GPC Signals, we will recognize and apply the GPC Signal to inactivate all of the cookies for that website, except for cookies that are necessary for the website to operate (“Strictly Necessary Cookies”). Additionally, if you are accessing our websites from one of these states, you can determine if your browser GPC Signal has been recognized by clicking on the “Your Privacy Choices” link in the footer of the website that will include a short message at the top of the preference center indicating that your GPC Signal has been received. For users from states not currently requiring recognition of the GPC Signal, our website servers may recognize and apply the GPC Signal for only targeted advertising cookies, but will not apply the GPC Signal to functional, performance or social media cookies. Further, a specific GPC Signal acknowledgement notice will not be included in the preference center, but you can always check and adjust your cookie settings by going to the Your Privacy Choices link in the footer of this website.
Where allowed by law, as described above, we use your Personal Data to provide you with targeted advertisements or marketing communications we believe may be of interest to you. In some jurisdictions, you may have the right to opt out of these types of targeted advertisements. See the Opt-out of Sale or Sharing or Processing of Sensitive Data section below to do so.
For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page by going to http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.
You can opt out of some targeted advertising using the below links:
Additionally, you can opt-out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/.
Certain of Roche’s practices may be considered the sale or sharing of Personal Data under applicable law. You may have the right to opt-out of the sale of Personal Data, opt-out of sharing of Personal Data for purposes of cross-context behavioral advertising, which in other states is the right to opt-out of targeted advertising, and the right to limit the use of sensitive Personal Data. To exercise these rights, please see the “Your Rights Regarding Your Personal Data” section below.
To the extent we offer any public or group forums on our Products and Services, such as newsfeeds, blogs, message boards, or similar tools (“Interactive Features”), the posts or comments you make may be public and viewed by others. You should use care before posting information about yourself, including Personal Data. You acknowledge and understand that you have no expectation of privacy or confidentiality in the content you submit to Interactive Features over the Products and Services. Except when required to do so by applicable law, we assume no obligation to remove Personal Data you post on our Products and Services, and your disclosure of any Personal Data through the Interactive Features is at your own risk.
___________________________________________________________________________________
Service providers acting on our behalf must execute agreements requiring them to maintain confidentiality and to process Personal Data as necessary to perform their functions in a manner consistent with this Notice, other applicable privacy notices, and as explicitly permitted or required by applicable laws, rules, and regulations.
We may combine information we collect, including Personal Data, with Personal Data that we may obtain from third parties.
Our Products and Services may contain links to other websites, applications, products, or services that are not owned or operated by Roche, such as social media websites and applications like Facebook and Twitter. You should carefully review the privacy policies and practices of other websites, products, and services as we cannot control and are not responsible for privacy policies, notices, or practices of third-party websites, applications, products, and services.
___________________________________________________________________________________
Please note that in many circumstances, we cannot effectively do business with you without processing some Personal Data about you (e.g., your contact information). For example, when you contact our customer service representatives, we may require you to provide information to authenticate your identity to assist you with your request. If you are unable to provide this information, we may be unable to process your request.
To the extent that the state in which you live has a data protection law that requires us to offer some or all of the following rights to you, we will provide the following rights to you based on your state’s law:
You can opt-out of sharing personal data or opt-out of targeted advertising for any website you visit by clicking on the Your Privacy Choices link located at the bottom of that website. To learn if you have the other above rights in the state in which you live and to exercise any of these rights with respect to your Personal Data, please complete the form located here or, if you prefer, you can call us toll-free at (800) 975-7105. We will not discriminate against you for exercising any of the rights described above, although we may not be able to continue to provide you Products and Services or it may otherwise affect the way we are able to interact with you.
We will make reasonable efforts to respond promptly to your requests in accordance with applicable laws. We may, after receiving your request, require additional information from you to honor your request and verify your identity. Please be aware that we may be unable to afford these rights to you under certain circumstances, such as if we are legally prevented from doing so.
In the event you wish to make a complaint about how we process your Personal Data, please contact us at uspriv@roche.com and we will handle your request as soon as possible. Even if you make a complaint to us, you may always lodge a complaint with the relevant authority in your location.
When we receive your Personal Data from our customers and process your Personal Data on their behalf, we do so at their request and subject to their instructions. We do not have control over our customers’ privacy and security practices and processes. If your Personal Data has been submitted to us by a Roche customer and you wish to exercise any of the above-mentioned rights, please contact the relevant customer directly.
___________________________________________________________________________________
Consistent with applicable laws and requirements, Roche has put in place physical, technical, and administrative safeguards designed to protect Personal Data from loss, misuse, alteration, theft, unauthorized access, and unauthorized disclosure consistent with legal obligations and industry practices. However, as is the case with all websites, applications, products, and services, we unfortunately are not able to guarantee security for data collected through our Products and Services. In addition, it is your responsibility to safeguard any passwords, ID numbers, or similar individual information associated with your use of the Products and Services.
___________________________________________________________________________________
We generally retain Personal Data for as long as needed for the specific business purpose or purposes for which it was collected. In some cases, we may be required to retain Personal Data for a longer period of time by law or for other necessary business purposes. Whenever possible, we aim to de-identify the information or otherwise remove some or all information that may identify you from records that we may need to keep for periods beyond the specified retention period.
___________________________________________________________________________________
If you are a patient, please note that this Notice is distinct from your Healthcare Provider’s HIPAA Notice of Privacy Practices, which describes how your Healthcare Provider uses and discloses individually identifiable information about your health that it collects, as well as any other privacy practices it applies. Roche collects, uses, and discloses any Personal Data it receives from your Healthcare Provider in accordance with its HIPAA-required agreements with your Healthcare Provider.
___________________________________________________________________________________
We reserve the right to change this Notice from time to time. We will alert you when changes have been made by indicating the date this Notice was last updated as the date the Notice became effective or as otherwise may be required by law. It is recommended that you periodically revisit this Notice to learn of any changes.
___________________________________________________________________________________
If you have questions or comments about this Notice or about how your Personal Data is processed, please contact us by one of the methods below:
Email: uspriv@roche.com
Mail: Roche Diagnostics Solutions/Roche Information Solutions, Attn: Privacy Office, 4300 Hacienda Drive, Pleasanton, CA 94588
Phone: (800) 975-7105
We will make reasonable efforts to respond promptly to your requests in accordance with applicable laws. Note that your request to exercise your data privacy rights must be done through the web form and 800 number listed under Your Rights Regarding Your Personal Data. We may, after receiving your request, require additional information from you to honor your request and verify your identity. Please be aware that we may be unable to afford these rights to you under certain circumstances, such as if we are legally prevented from doing so.