Data Privacy Notice
Last modified August 6, 2024
We take your data privacy and the protection of your personal data seriously and our data privacy principles provide fundamental guidance to all our businesses worldwide. We comply with applicable national regulations and our understanding of data privacy is based on the European General Data Protection Regulation (GDPR), amended by local regulations in case they are stricter.
1. Preamble
This data privacy notice is addressed to all customers, vendors, suppliers, contact persons, and other individuals ("Data Subjects", "you") of or in contact with Merck Life Science Private Limited, Merck Specialities Private Limited, Sigma-Aldrich Chemicals Private Limited and Merck Performance Private Limited ("Merck", "us", "we"). It is meant to help you understand what personal data we collect, why we collect it, and how you can exercise your data protection rights. "Personal Data" in this document is any information relating to an identified or identifiable natural person, by direct or indirect means. In some countries, this would also be called “personally identifiable information”.
We develop products and technologies in three different business sectors which we name Healthcare, Life Science, and Electronics to enable brilliant people to solve global challenges. In these contexts, we process your personal data in various ways, depending on your specific role, the way we communicate and the products or services you use. Section 3 of this data privacy notice contains further details to guide you through each individual situation.
Please click here to view the privacy statements by location, and here to view the HCP Privacy Statement. Should you have questions or queries regarding the processing of your personal data, please contact our Group Data Privacy Officer via privacy@merckgroup.com or the other contact details provided below.
2. General Information
This section is about the controller of your personal data, how you may contact this controller and which rights you have as a data subject in this context. A controller is a company responsible for the handling of personal data.
2.1 Controller
The data controller means the company (legal person) who determines the purposes and means of processing of your personal data. For the overarching processing activities described in this data privacy notice, Merck is the data controller. In addition, any affiliate of Merck that processes personal data might become a controller or joint controller of such data. This includes, without limitations, any legal entity of the Merck group you enter into an agreement with.
2.2 Data Privacy Officer
We have appointed a Data Privacy Officer. You can contact this person and the team at any time:
Data Privacy Officer
privacy@merckgroup.com
You are also welcome to exercise your data protection rights by submitting your request directly in our Data Privacy Portal.
3. The Processing Activities in Detail
This section explains the different data processing activities in which we process your personal data.
3.1 Processing of Your Personal Data in Various Contexts
We process your personal data in various situations we are describing in this section, including any of your on and offline interactions with us regarding the products and services we offer and the business we do.
We usually process your personal data for contractual purposes and to communicate with you for commercial reasons when you or we purchase a good or service from the other one. For this purpose, we only process such data which is needed to fulfill the contract itself and with all additional obligations we are subject to, like tax payments.
In addition, we might use some of your personal data, based on our legitimate interest, to develop and offer our products and services, learn more about your interests, do marketing under local market rules, and continuously improve our offerings.
We also process personal data for our scientific research as a global science and technology company, based on our legitimate interest, your consent, or as allowed for such research.
Please refer to the below explanations and/or individual data privacy notices which we provide in the context of our business communication with you to learn more about the corresponding processing of your personal data in this context.
3.1.1 Contract Initiation and Fulfilment
Merck processes your personal data for the initiation and the fulfilment or performance of contracts, including the administrative management of related order inquiries and assignments, both on and offline.
This processing activity may include the following data categories:
- Your contact information (e.g., name, title, form of address, private address, gender, telephone numbers, email address, place of work, etc.);
- Your payment details (e.g., bank account number, bank code, credit institute, tax identification number).
The processing of these personal data is necessary for the performance of a contract with you as an individual or is necessary to safeguard our legitimate interests of conducting business with your employer. Without your provision of your data, we cannot establish and maintain contact with you in the context of the specific contract.
3.1.2 Purchase and Use of Goods and Services
If and to the extent that we provide services or goods to you, or receive them from you, we may process your personal data, e.g., to receive your services and/or provide our goods and prepare invoicing.
This processing activity may include the following data categories:
- Your contact information (e.g., name, title, form of address, private address, gender, telephone numbers, email address);
- Accounting data (e.g., purchased goods and services, bank details, customer number, tax identification number, tax category);
- Details on your profession (e.g., job title, position, personnel number, place of work, branch office, department).
The processing of these personal data is based on the necessity for the performance of a contract with you as an individual or is necessary to safeguard our legitimate interests of conducting business with your employer. Without your provision of these personal data, we usually cannot establish and maintain contact with you, issue and receive invoices as well as receive or deliver services and/or goods in the context of the specific contract.
3.1.3 Account Creation
You can register on some of our Websites and create an account. When logging in as a registered user, we collect personal data resulting from the registration form marked as mandatory.
This processing activity may include, among others, the following data categories:
- Your contact information (e.g., name, title, form of address, private address, gender, telephone numbers, email address);
- Accounting data (e.g., purchased goods and services, bank details, customer number, tax identification number, tax category);
- Details on your profession (e.g., job title, position, personnel number, place of work, branch office, department).
The data will be processed and used by us for the entire time your account exists, for our service and technical administration and – to the legally permissible extent – for our own marketing purposes. The processing of these personal data is based on the necessity for the performance of a contract with you or is necessary to safeguard our legitimate interests of conducting business with you.
3.1.4 Marketing Communications
We process your personal data within the scope of our public relations and marketing processes. This includes in particular the issuance of newsletters, press kits, and registrations for press distribution lists, press contacts and press representatives.
3.1.4.1 Newsletters
This processing activity may include the following data categories:
- Your contact information (e.g., name, title, form of address, private address, gender, telephone numbers, email address);
- Details on your profession (e.g., job title, position, personnel number, place of work, branch office, department).
If you would like to subscribe to any of our available newsletters, you may enter your email address in our registration form and click the "Send" button. You will then receive an email from us to your email address. You may complete the registration by verifying your email address by using the answer function in your email program.
This processing activity includes the following data categories: The information you provided to subscribe, such as your title, name, email address and personal/professional interests.
The processing is based on your consent you provided to us in the course of the subscription process. Your personal data will be deleted when you withdraw your consent, e.g., by filling the form on our website to unsubscribe.
3.1.4.2 Other Processing for Marketing; Profiling
Other processing in this regard is based on our legitimate business interests. We have a legitimate interest in informing our clients of news, events, etc. to gain new leads and establish and maintain a long-term business relationship.
We aim to present you information that could be of interest to you and to communicate seamlessly over various channels (phone, email, SMS, mail, social media messages) without sending redundant information. Our communication with you is based on the information we collect about you and are permitted to use. For example, we use the combination of your email address and your browsing data so we can provide you with information about a product you look up on one of our websites. Based on the information we collect, we may internally indicate that you are interested in certain categories of information.
We also use profiling procedures to optimize and personalize our customer relationship management and our advertising measures. To optimize and personalize our advertising measures, we create customer profiles and assign customers to specific customer segments on the basis of these customer profiles. On the basis of this segmentation, we can manage the type, content and frequency of specific advertising measures for specific target groups. For profiling purposes and based on our legitimate interest, we use data that we receive from you as part of our business relationship. This includes personal data, like your purchasing behavior and browsing behavior. Profiling may also be related to usage data that we create by measuring and evaluating the customer's interaction with electronic advertising, and in particular by measuring and evaluating the opening and click rate in email newsletters.
3.1.5 Business Contacts
If Merck has received your contact details from business events, for example as part of a business appointment (e.g., by exchanging business cards) or as part of an assignment, we use your contact and business details to maintain our business contacts. For this purpose, we usually transfer your contact details to our CRM (Customer Relationship Management).
This processing activity may include the following data categories:
- Your contact information (e.g., name, title, form of address, private address, gender, telephone numbers, email address);
- Details on your profession (e.g., job title, position, personnel number, place of work, branch office, department, qualifications).
This data processing is based for our legitimate business interests. Merck has a legitimate economic interest in maintaining contacts beyond the initial contact and in using them to establish and develop a business relationship and to remain in contact with the parties concerned. Such business contacts could also be easily processed in our e-mail communication with you and then kept in typical business software, either centrally or on the electronic devices of our employees.
3.1.6 Contact Forms and Service Requests
We process your personal data, if you enter and submit your data via one of our contact forms or contact us otherwise, e.g., in the context of a service request or via the contact form we provide on our Websites. Your data will also be processed to handle your specific request, e.g., by answering or forwarding your request to a competent department. Your personal data will only be processed for the purpose of responding to your inquiry.
This processing activity may include the following data categories:
- Your contact information (e.g., name, title, form of address, private address, gender, telephone numbers, email address);
- Details on your profession (e.g., job title, position, personnel number, place of work, branch office, department, qualifications);
- Any further information you provide to us, e.g., in the process of your request or which is otherwise required to answer your request.
The processing and use of your data are necessary for answering your inquiry in a quick and competent manner and is based for the rest on our legitimate interest to communicate with our contacts and customers and in particular provide customer service. The processing of your personal data is necessary to process your inquiry and establish or maintain contact.
3.1.7 Accounting
Merck may process your personal data for the purpose of an orderly and lawful accounting. This is necessary e.g., to process and record invoices, issue monetary compensation or refunds and to verify claims. In addition, Merck is subject to legal documentation and retention obligations based on tax and accounting laws which also involve the processing of your personal data. The record keeping, documentation and archiving of such documents at Merck usually takes place in our IT systems and in some cases also in the form of paper files.
This processing activity may include the following data categories:
- Your contact information (e.g., name, title, form of address, private address, gender, telephone numbers, email address, etc.);
- Accounting data (e.g., purchased goods and services, bank details, customer number, tax identification number, tax category, etc.);
- Details on your profession (e.g., job title, position, personnel number, place of work, branch office, department, etc.).
The data processing is necessary for Merck to manage, document, maintain and archive files and documents to fulfill our legal obligations under tax, commercial and corporate laws. If and to the extent such laws do not apply for the processing of your personal data in this context, this processing activity relies on our legitimate business interest to establish and maintain an adequate accounting process, in particular to issue or settle invoices.
3.1.8 Healthcare
We may process your personal data for the purpose of maintenance and improvement of health-related topics by developing and applying measures to prevent, diagnose, treat, recover, or cure diseases, illness, injuries, and other physical and mental impairments. We process personal data especially in the fields of general medicine, endocrinology, fertility, neurology, immunology, and oncology.
This processing activity may include the following data categories:
- Your contact information (e.g., name, title, form of address, private address, gender, telephone numbers, email address, date and place of birth, country of birth, nationality, etc.);
- Health information (e.g., diagnosis, existence of an illness or disability, details about accidents, treatment history, relevant health parameters, etc.).
In these cases, the legal basis of the data processing depends on the specific context. The processing can be necessary to safeguard our legitimate interests for the purposes of maintaining and improving health-related matters. We are also required to process your personal data where we have a respective legal obligation. Furthermore, we process your data if you have expressly consented to the processing in question, e.g., regarding the processing of your special categories of personal data (in particular your health data). Please click here to view the HCP Privacy Statement.
3.1.9 Life Science
We may process your personal data within the context of scientific research and our Life Science business. This includes for example processing of Data Subjects that work in the fields of drug research, biopharmaceutical production, biotechnology, industrial microbiology, clinic and diagnostics, food analysis, quality control for pharmaceuticals, governmental and academic research, and environmental analyses.
This processing activity may include the following data categories:
- Your contact information (e.g., name, title, form of address, private address, gender, telephone numbers, email address, date and place of birth, country of birth, nationality, etc.);
- Health information (e.g., diagnosis, existence of an illness or disability, details about accidents, treatment history, relevant health parameters, etc.).
In these cases, the legal basis of the data processing depends on the specific context. This processing can be necessary to safeguard our legitimate interests for the purposes of maintaining and improving health-related matters as well as scientific research and to sell our Life Science products. We are also required to process your personal data where we have a respective legal obligation. Furthermore, we process your data if you have explicitly consented to the processing in question, e.g., regarding the processing of your special categories of personal data (in particular your health data).
3.1.10 Electronics
We process your personal data in the context of our Electronics business offerings related to architecture, such as energy-efficient windows, smart glass and façades, innovations in mobility, display applications, plastics and specialty coatings, innovative semiconductor materials, cosmetics and high-tech chemicals for advanced industries such as photonics, solar, and lighting.
This processing activity may include the following data categories:
- Your contact information (e.g., name, title, form of address, private address, gender, telephone numbers, email address);
- Details on your profession (e.g., job title, position, personnel number, place of work, branch office, department, education).
The data processing is based on the necessity for the performance of a contract with you as an individual or is necessary to safeguard our legitimate interests of manufacturing, distributing, selling, and improving our Electronics products as well as scientific research. We have a legitimate economic interest to process personal data for the purpose of developing innovative and appealing products to increase sales, monitor technological developments and develop commercial business models.
3.1.11 SpeakUp Line
We also process data collected within the scope of our whistleblower system ("SpeakUp Line") exclusively for the processing and follow-up of the reports received, where employees as well as external stakeholders can inform us confidentially about potential violations of rules and laws and non-compliant behavior so that we can investigate in such issues.
In such cases, we process the description of the issue (including time, place and persons involved) which we receive from the person who issued the notification. We may process further personal data, which is required to clarify and solve the issues which we investigate.
This processing is based on our legitimate interest to avoid financial and reputational damages caused by compliance issues. The use of our whistleblower system is entirely voluntary and always possible in an anonymous way for the whistleblower. Further information on the processing of personal data in this context can be found in the data privacy statement for our SpeakUp Line under the following link: https://evarooms.merckgroup.com/Topic/SPEAKUPLINE/en-us/data-privacy or www.bkms-system.net/ISPEAKUP.
3.1.12 Event Management
We process your data for events we either provide on our own or for which we act as a sponsor and receive certain information about you. These events could vary from a singular meeting to a conference over several days, publicly accessible or addressed only to a specific audience, in our own facilities or other locations.
Depending on the event, the data we collect varies and could contain:
- Your contact information (e.g., name, title, form of address, private address, gender, telephone numbers, email address),
- Details on your profession (e.g., job title, position, personnel number, place of work, branch office, department, education),
- Information about your travel to the event (e.g., hotel accommodation, flights, transportation),
- Your bank account data in case of payments to you as a speaker or reimbursements of your costs for participation.
Such data is typically used for the participation in the event. In case of payments, we might be required to report them to authorities (e.g., tax authorities).
3.1.13 Research and Development
We perform different surveys, market analyses, and scientific research. This includes customer satisfaction, the development of new products or services or even predictive analyses of future behavior of customers or market developments.
The data we collect for such processing activities varies broadly depending on the specific purpose. If possible, we pseudonymize or even anonymize personal data before or in the course of our analyses. In most cases, in particular, when the processing requires and identifier that might lead to you as an individual, we ask for your consent prior to such processing.
We also collaborate with other companies or institutes in case of scientific research. In such cases, we enter into specific agreements with these third parties to value the confidentiality of your data.
3.1.14 Site Management
When visiting our facilities, we might process your personal data as part of our visitor management. We might offer parking space for your car or provide you with internet connectivity via our Wi-Fi network.
This includes mainly:
- Your contact information (e.g., name, title, form of address, private address, gender, telephone numbers, email address),
- Details on your profession (e.g., job title, position, personnel number, place of work, branch office, department, education),
- Details on the visit on in our facilities (e.g., data of visit, purpose of visit, contact person at Merck).
As a part of our security concept, we also maintain a series of technical and organizational measures to protect our facilities, including CCTV. We process only such data which is necessary to maintain this level of security based on our legitimate interests or legal obligations we are subject to.
3.2 Privacy Notice for this Website
This section explains the different data processing activities in which Merck processes your personal data for the operation of the services provided on this website ("Websites").
3.2.1 Operation of our Websites
We process your personal data for the purpose of the operation of our Websites. You can access our Websites without directly providing personal information. However, whenever you access our Websites, you automatically transfer personal data to our servers for technical reasons.
This processing activity may include the following data categories:
- IP address of the requesting device;
- Date and time of your visit;
- Name and URL of the retrieved file;
- Transferred data volume;
- Access status (file transferred, file not found, etc.);
- Identification data of the browser and operating system used;
- Name of the provider of user's internet access; and
- Website from which access is made and the Websites you are accessing.
This data processing is based on our legitimate business interests. We process these data for the purpose of presenting our Websites and to ensure its technical stability and security (e.g., to prevent hacker attacks).
3.2.2 Cookies
Cookies improve the user experience on our Websites because they allow, e.g., the system to recognize returning visitors. The term "cookies" in this Privacy Notice refers to cookies and similar technologies. Cookies are small, usually randomly coded text files that are sent to your device and stored there. These cookies allow your browser to track certain information that may be retrieved and used by internet servers at a later stage. Merck uses cookies and similar technologies on its Websites for several reasons, for example:
- Websites load faster;
- Websites may be browsed faster;
- Your settings, such as language and time zone, may be saved;
- Security on websites is improved since your identity may be verified; and
- Your log-in to secured websites is facilitated.
We include the following three categories of cookies on our Websites:
3.2.2.1 Necessary Cookies
These cookies are necessary to safeguard the functionalities of our Websites, the services provided thereon and for the website to operate. Cookies are set in response to your actions and depend on your specific service requests (e.g., setting your privacy preferences, filling out forms, or logging in). More specifically, we set the following cookies:
- ___utmvc: This cookie is set by a third-party service to filter out malicious requests. It is deleted within 29 seconds.
- _abck: This cookie is used as part of the behavior anomaly detection method of Bot Manager Premier, it is also known as the long-term cookie. It is used to track a user's past behavior (human / bot) on a protected site. It is deleted within 1 year.
- ak_bmsc: This cookie is used to track the progress of the session going through the standard detection workflow. When present, it is also used as the identifier instead of the IP address for the bot rate control rules. It is deleted within 2 hours.
- ak_wfSession: This cookie is used as part of the Bot Manager Standard and Bot Manager Premier workflow validation feature. It is deleted within 2 hours.
- ASP.NET_SessionId: This cookie is automatically generated by asp.net. It is created the first time the application is accessed over the browser and deleted when you close your browser.
- AWSALBCORS: This cookie is managed by Amazon Web Services (AWS) and is used for load balancing. It is deleted within seven days.
- AWSELBCORS: With CORS (cross-origin resource sharing) requests, some browsers require SameSite=None; Secure to enable stickiness. In this case, Elastic Load Balancing creates a second stickiness cookie, AWSELBCORS, which includes the same information as the original stickiness cookie (AWSELB) plus this SameSite attribute. It is deleted when you close your browser.
- bm_mi: This cookie is used to track the progress of the session through the browser validation detection method. It is deleted within 2 hours.
- bm_sv: This cookie is used as part of the session validation detection method and keeps track of the number of HTML pages and Ajax requests the client makes. It is deleted within 2 hours.
- bm_sz: This cookie is used as part of the behavior anomaly detection method of Bot Manager Premier, it is also known as the short-term cookie. It references the telemetry collected during the session. It is deleted within 4 hours.
- mediaCart: This cookie is used to store files the user adds to their media and files shopping cart. The user's session will be stored within a cookie. This cookie expires after 30 days.
- sec_cpt: This cookie is used as part of the challenge action (Captcha, PoW, behavioral) available in the behavior anomaly detection method of Bot Manager Premier. This cookie tracks the state of the challenge process. It is deleted within 5 to 120 minutes.
The processing is based on our legitimate business interest to be able to provide our basic web services in a secure and useful manner. Our website cannot function without these cookies, and they can only be disabled by changing your browser preferences. Please note, if you object to the use of these necessary cookies, our Services might not be available to you.
3.2.2.2 Functional Cookies
These cookies enable the provision of advanced functionalities and are used for personalization. The cookies are set in response to your actions and depend on your specific service requests (e.g., pop-up notification choices). More specifically, we set the following cookies:
- AKA_A2: This cookie provides an Advanced Acceleration feature, which enables DNS Prefetch and HTTP2 push. It expires after 1 hour or upon the withdrawal of your consent.
- AkamaiAnalytics_BrowserSessionId: This cookie assigns an anonymous identifier to each visitor who plays a video. Used to analyze the video media player. It expires when you close your browser or upon the withdrawal of your consent.
- FORMASSEMBLY: This cookie is used to provide our users with online forms. The user's session will be stored within a cookie. It expires when you close your browser or upon the withdrawal of your consent.
- has_js: This cookie is used to indicate whether or not the visitor´s browser has JavaScript enabled. It expires when you close your browser or upon the withdrawal of your consent.
- HTML_BitRateBucketCsv: This cookie measures the playback time of videos in the video media player per visitor depending on the bit rate. Used to analyze the video media player. It expires when you close your browser or upon the withdrawal of your consent.
- HTML_isPlayingCount: This cookie counts the number of times a specific video was played in the video media player. Used to analyze the video media player. It expires when you close your browser or upon the withdrawal of your consent.
- HTML_VisitCountCookie: This cookie counts the number of views of a video in the video media player. Used to analyze the video media player. It expires when you close your browser or upon the withdrawal of your consent.
- HTML_VisitIntervalStartTime: This cookie measures the start time of an interval between visits to a website in the video media player. Used to analyze the video media player. It expires when you close your browser or upon the withdrawal of your consent.
- HTML_VisitValueCookie: This cookie calculates the value of the visit to the website from the playback time of a video in the video media player when it is accessed and the number of rebuffer processes during playback. Used to analyze the video media player. It expires when you close your browser or upon the withdrawal of your consent.
- incap_ses_...: This cookie is used for visitor recognition. It expires when you close your browser or upon the withdrawal of your consent.
- m_survey47_2_1: This cookie is used for ensuring the technical process of the survey. It expires after 365 days or upon the withdrawal of your consent.
- merck_survey_svsc: This cookie is used to offer surveys to randomly selected users on the website. It expires after one minute or upon the withdrawal of your consent.
- merck_survey…: This cookie is used to offer surveys to randomly selected users on the website. It expires after one year or upon the withdrawal of your consent.
- merck_survey32_1_1: This cookie is used for ensuring the technical process of the survey. It expires after 365 days or upon the withdrawal of your consent.
- merck_survey32_2_1: This cookie is used for ensuring the technical process of the survey. It expires after 365 days or upon the withdrawal of your consent.
- muser: This cookie is used to detect if the user is a Merck KGaA employee based on their IP address. It expires after 30 days or upon the withdrawal of your consent.
- nxrCookieAgreement: This cookie is used to collect and store user consent to the use of cookies. It expires after one day or upon the withdrawal of your consent.
- RT: This cookie is used to interface with LinkedIn. It expires after seven days or upon the withdrawal of your consent.
- VISITOR_INFO1_LIVE: This cookie is used to estimate user bandwidth on pages with built-in YouTube videos. It expires after six months or upon the withdrawal of your consent.
- water-webgl-open-ids: This cookie is used for animated pages. The cookie is deleted when you close your browser or upon the withdrawal of your consent.
The processing is based on your consent you provided to us. You either grant your consent by accepting all cookies in our cookie banner or by activating the cookie type(s) you have selected. Your consent is voluntary, and you may withdraw it at any time with effect for the future. You can withdraw your consent by reopening our cookie banner and deactivating the cookie type. If you do not grant your consent or withdraw it, this will not result in any disadvantages for you. However, without your consent, the functions explained above might not be available to you.
3.2.2.3 Targeting Cookies
These cookies may be set to analyze your interests and show you relevant ads on other websites. These cookies work by uniquely identifying your browser and device. By integrating these cookies, we aim to learn more about your interests and your behavior on our Websites in order to place our advertising in a targeted manner. More specifically, we set the following cookies:
- _fbp: This cookie is used by Facebook to deliver a series of advertisement products on Facebook. It expires after three months or upon the withdrawal of your consent.
- _ga: This cookie is associated with Google Universal Analytics (Google LLC) – an update to Google LLC's more commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a customer identifier. It is included in every page request on a website and is used to calculate visitor, session and campaign data for website analytics reports. By default, it is set to expire after 2 years or upon the withdrawal of your consent.
- _gat…: This cookie is linked to Google Universal Analytics (Google LLC). It is used to throttle the request rate and limit data collection on high-volume websites. This cookie expires after 10 minutes or upon the withdrawal of your consent.
- _gat_UA-43815746-1: This cookie is used by Google Analytics to limit the request rate. It expires after one minute or upon the withdrawal of your consent.
- _gat_gtag_UA_43815746_1: This cookie is used to deliver adverts more relevant to you and your interests. It is also used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising campaign. It expires after one minute or upon the withdrawal of your consent.
- _gid: This cookie contains a randomly generated user ID. This ID allows Google Analytics (Google LLC) to recognize returning users to this website and merges data from previous visits. It expires after one day or upon the withdrawal of your consent.
- _guid: Used to identify a LinkedIn Member for advertising through Google Ads. It expires after 90 days or upon the withdrawal of your consent.
- BiographicsOptOut: Determine opt-out status for 3rd party tracking. It expires after 10 years or upon the withdrawal of your consent.
- IDE: This cookie contains a randomly generated user ID. This ID allows Google LLC to recognize you on multiple websites and provide personalized ads. It expires after one year or upon the withdrawal of your consent.
- did: Remarketing of users of the Merck website for commercial purposes. It expires after one year or upon the withdrawal of your consent.
- igodigitalst: This cookie is used to capture customer behavior to improve the quality of the experience of our online customers, including enhanced browsing experiences. It expires after one hour or upon the withdrawal of your consent.
- igodigitalstdomain: This cookie is used to capture customer behavior to improve the quality of the experience of our online customers, including enhanced browsing experiences. It expires after one hour or upon the withdrawal of your consent.
- igodigitaltc2: This cookie is used to capture customer behavior to improve the quality of the experience of our online customers, including enhanced browsing experiences. It expires after 10 years or upon the withdrawal of your consent.
- test_cookie: Is set as a test to check whether the browser allows cookies to be set. Does not contain any identification features. It expires after 15 minutes or upon the withdrawal of your consent.
- U: Browser Identifier for users outside the Designated Countries. It expires after 3 months or upon the withdrawal of your consent.
- visid_incap_...: This cookie is used for visitor recognition for linking certain sessions to a specific visitor. It expires after one year or upon the withdrawal of your consent.
- YSC: This cookie is used to register a unique ID to keep statistics of YouTube videos that the user has seen. It expires when you close your browser or upon the withdrawal of your consent.
- zuid: Holds the anonymous user's ID. Used for tracking user actions, such as clicks on the recommendations. It expires after 90 days or upon the withdrawal of your consent.
The processing is based on your consent you provided. You either grant your consent by accepting all cookies in our cookie banner or by activating the cookie type(s) you have selected. Your consent is voluntary, and you may withdraw it at any time with effect for the future. You can withdraw your consent by reopening our cookie banner and deactivating the cookie type. If you do not grant your consent or withdraw it, this will not result in any disadvantages for you. However, without your consent, the functions explained above might not be available to you.
Please note that the use of Google Analytics has been extended by the plug-in "AnonymizeIP", to ensure an anonymized collection of your IP address, so that we cannot relate your data to your person. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.
3.2.2.4 Management and Deletion of Cookies
You can manage your decision on the use of cookies by reopening our cookie banner or by changing your browser preferences. Some computer browsers automatically accept all cookies. In this case, you may not see the cookie banner which allows you to manage your cookies individually. However, you can change your browser settings to block all cookies. You may also be able to configure your browser settings so that only certain types of cookies are blocked or so that you are notified as soon as a new cookie is to be stored on your computer. In this case, you can accept or reject cookies individually. If this function is available to you, you will find more detailed explanations in the help function of your browser. There you will also find information on how to delete all or certain cookies for which you have given us your consent. For more information on managing and deleting cookies for popular browsers, please see the following links: Google Chrome, Mozilla Firefox, Microsoft Internet Explorer, Microsoft Edge, Apple Safari.
3.2.3 Google Maps
We process your personal data to display maps, a service provided by Google LLC.
This processing activity may include the following data categories which will be transmitted to Google LLC in the United States of America:
- The technical data as described in Section 4.1;
- Your location;
- The content you access (e.g., places); and
- The frequency of these accesses.
The processing is based on our (and your) legitimate business interest to guide you to our premises and facilitate your route planning.
The use of the service is not possible without your data, and these are automatically provided when you open a sub-page on which Google Maps is integrated. We process no further personal data than those specified in Section 4.1. Information on data processing by Google can be found in Google's privacy policy under the following link: https://policies.google.com/privacy?hl=en.
We do not conduct automated decision-making or profiling in this context.
3.2.4 Social Media Plugins
We use social media plugins from various social networks (e. g. Facebook). With the help of these plugins, you can share content or recommend products. The plugins are deactivated by default and therefore do not send data to other websites. By clicking on the symbol of such social network on MerckGroup.com and the confirmation by a second click on "OK" on the site following, you can activate plugins and thus provide your consent to the processing of your personal data in this context (so-called 2-click solution).
If these plugins are activated, your browser establishes a direct connection with the servers of the respective social media network as soon as you access the operator's website. The content of the respective plugin is transmitted directly from the social media network to your browser and embedded into the website.
By embedding the plugins, the social media network receives the information that you have visited the respective page of the operator. If you are logged in to the social media network, it can allocate the visit to your account. When you interact with the plugins, the corresponding information is transferred directly from your browser to the social media network and stored there.
Even if you are not logged in to social media networks, websites with active social media plugins can still send data to these networks. With an active plugin, a cookie with an identifier is placed each time the website is accessed. Since your browser sends this cookie every time you connect to a network server without being asked, the network could basically use it to create a profile of the websites visited by the user associated with the ID. And it would then also be possible to assign this identifier to a person again later – for example when logging on later to the social network.
For the purpose and scope of data collection and the further processing and use of the data by social media networks, as well as your rights and options for the protection of your privacy, and in particular your right to revoke your consent, please refer to the data protection notices of the respective networks.
- Facebook (provided by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304 USA): You can view Facebook’s privacy policy here:
https://www.facebook.com/about/privacy/your-info#public-info - Twitter (provided by Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA): You can view Twitter’s privacy policy here:
https://twitter.com/privacy - LinkedIn (provided by LinkedIn Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA): You can view LinkedIn’s privacy policy here:
https://www.linkedin.com/legal/privacy-policy - YouTube (provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA): You can view Google’s privacy policy here:
https://www.google.de/intl/de/policies/privacy/ - Instagram (provided by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA): You can view Instagram’s privacy policy here:
https://help.instagram.com/155833707900388
4. Data Retention
Unless otherwise stated in this Privacy Notice, your personal data are regularly deleted as soon as they are no longer necessary to fulfill the purpose of the processing, or the processing is otherwise inadmissible. This is usually the case if the data is no longer necessary to meet our business interests or for the provision of the services requested by you, no statutory data retention obligations apply, or you withdrew your consent.
For more information about how long we store cookies for, please see above.
Your IP address, which is collected while browsing our Websites, is stored for a period of time of 7 days unless a reasonably justified incident indicates a longer storage period (e.g., due to a hacking attack).
Under certain circumstances, your data must also be kept longer, e.g., if a so-called Legal Hold or Litigation Hold (i.e., a ban on deleting data for the duration of the procedure) is ordered in connection with official or legal proceedings. Data without any personal identifiable information may be stored permanently.
5. Recipients of Personal Data
We might transfer your personal data to third parties, such as our service providers, financial institutions to process payments, lawyers and auditors, etc. to the extent required to meet our business objectives and fulfill our Services. For this purpose, we enter into adequate data protection agreements with these parties to the extent legally required and in this context safeguard that these recipients agree on technical and organizational measures to protect your personal data adequately.
We might also transfer personal data to other Merck Group companies.
6. DATA TRANSFER TO THIRD COUNTRIES
Should such a data transfer involve the transferal of your personal data to countries outside of the EU/EEA, that do not have an adequate level of data protection compared to the EU, we safeguard such level of data protection by entering into standard contractual clauses with any such recipients if no adequacy decision justifies such transfer. This ensures that your data protection rights are protected. You may download a copy of these standard contractual clauses at the following URL: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en
7. AUTOMATED DECISION-MAKING
We generally do not use automated decision-making within the meaning of Article 22 GDPR. If we make use of automated decision-making or profiling, you will be informed through a separate data privacy notice.
8. OBLIGATION TO PROVIDE PERSONAL DATA
In general, you are neither contractually nor statutorily obliged to provide your personal data for the above purposes, however your decision to not provide your data may reduce features and functionalities, the impossibility to use our information and services offered in this context, the denial of access to our services and/or exclusion from our business activities to the extent the processing of your personal data is key in these contexts.
The information required for registration on our Website or for contacting us is marked as mandatory in the corresponding area (e.g., a contact form) of the Website; if you do not provide this mandatory information, we cannot enable you to use the respective functionality.
9. YOUR DATA PROTECTION RIGHTS
You have or might have the following data protection rights:
- Right of access: You have the right to obtain information on the processing of your personal data and to receive a copy these data.
- Right to rectification: You have the right to request that we correct or complete your inadequate, incomplete or inaccurate personal data.
- Right to erasure: Under certain circumstances, you have the right to request that we delete your personal data.
- Right to restriction of processing: Under certain requirements, you may request us to restrict the processing of your personal data.
- Right to data portability: You might have the right to receive your personal data in a structured, common and machine-readable format and request that these data are transferred to another data controller, if applicable under the specific circumstances.
- Right to object: You might have the right to object to the processing of your personal data by us, in particular if the processing of your personal data is based on (i) the necessity of the performance of a task in the public interest, or (ii) legitimate interests. We will then stop the processing of your personal data unless we remain legally authorized to do so.
- Right to lodge a complaint with a supervisory authority: You might have the right to lodge a complaint with a supervisory authority against the processing of your personal data if you believe that the processing of your personal data violates data protection regulations.
9.1 Exercise Your Data Protection Rights
You may exercise your data protection rights by submitting a request in our Data Privacy Portal. We take our responsibility for the protection of your rights very seriously. Our privacy experts will examine your request and answer it as soon as possible.
9.2 Withdrawal of Consent
In case you granted us your consent to process your personal data, you may withdraw this consent with effect for the future, depending on the specifications of the respective processing activity. We will then stop the processing of your personal data, unless we have a legal permission to do so. Please note that your withdrawal has effect for future processing operations only and does not make data processing operations, which we executed before such withdrawal, unlawful.
To withdraw your consent, you may send an email to service@merckgroup.com. If you withdraw your consent, you may no longer be able to use the services affected by the withdrawal. Apart from that, you will not suffer any further disadvantages.
If you do not specify your withdrawal to a specific processing operation, we will assume that you withdraw your consent regarding all processing of your personal data that is based on your consent.
This Data Privacy Statement is up-to-date and dates from April 2022. We reserve the right to amend the data privacy declaration at any time with effect for the future, in particular to adapt it to a further development of the website or the implementation of new technologies.
To continue reading please sign in or create an account.
Don't Have An Account?