DATA PRIVACY STATEMENT

Medford Rx Solutions Inc ("we" or "us") respects and is committed to the protection of your personal information and your privacy. This Personal Data Protection Notice ("Notice"), prepared in accordance with the Data Privacy Act 2012 (the "Act"), sets out our personal information protection practices that are put in place to protect the personal information of individuals whom we deal with.

Please note that we may amend this Notice at any time without prior notice and will notify you of any such amendments via our website or by email. Please check back regularly for updated information on the handling of your personal data.

1. Definitions

For the purposes of this Notice: (a)"channel partner(s)" means authorized service partner(s) and/or business partner(s); and (b)"personal information" and "processing" shall have the meanings as set out under the Act.

2. Collection of personal information

In the course of your dealings with us, we will request that you provide certain personal information elements to enable us to enter into transactions with you or to deliver the necessary goods, services and/or communications in connection with such transactions. These are necessary for our business process execution, including delivery of notices, services and/or products, customer or channel partner and/or third party vendor relationship management, planning purposes in connection with future products, including promotional events with our Affiliates and channel partners.

3. What kind of personal information we collect

In order for us to fulfill one or more of our obligations listed in paragraph 2 herein, we will need to collect relevant personal information from you. The personal information collected by us shall include any or all of the following:

  1. Contact information such as your name, date of birth, identification documents, gender, mailing address, phone number(s), prescription and name of your physician(when required)
  2. The status of products and/or services you have acquired from us or have subscribed to;
  3. Dosage and quantity of product prescribed and purchased from us;
  4. Your personal interests and preferences to help us tailor offerings on our products and/or services which would suit you best;
  5. Information you provide us regarding your promotional preferences or in the course of participating in patient programs; and
  6. CCTV or camera visual recordings when you visit our branches or participate in any of our events.

4. When and how we collect your personal information

We collect personal information directly from you when you:

  1. Visit our branches, communicate with us through our delivery hotline numbers, email address or Viber messages; when you download our MedExpress App; when you use or register in an e-consulting or telemedicine platform who are our partners and your e-prescription are received by our branches or call center; or when you visit our website to order medicines and other related products;
  2. Where you register your interest or subscribe for information on our products and/or services.(for example website information or other medical apps);
  3. Participate in any of our surveys and patient programs of our partner suppliers;
  4. Respond to any marketing materials we send out;
  5. Commence a business relationship with us (applicable to channel partner or third party vendors);
  6. Visit our offices; and/or
  7. Provide feedback to us (for e.g. via our website or in hard copy).

Other than personal information obtained from you directly (as detailed above), we may also obtain your personal information from third parties we deal with or who are connected with you where you have given your consent for disclosure and from such other sources where you have likewise given your consent for the disclosure of information relating to you, and/or where otherwise lawfully permitted.

5. Purpose of collecting personal information

Personal data you provide will be processed by us for the following purposes as applicable:

  1. The delivery of notices, services or products and the marketing of such services or products to you;
  2. To ensure the steady supply of goods and services;
  3. Such purposes specifically provided for in any particular service or product offered by us;
  4. Conducting marketing and customer profiling activities in connection with our services and related products;
  5. Our internal recordkeeping;
  6. Enabling us to send you information by e-mail, telecommunication means (telephone calls or text messages) or social media about products and services offered by our suppliers, that we think may interest you;
  7. To establish and better manage your medication needs;
  8. To process any communication you send us (for example, answering any queries and dealing with any customer service complaints and feedbacks);
  9. Post-sales services, such as customer service-related matters;
  10. To provide you with the products and/or services you have requested; and/or
  11. To notify you about benefits and changes to the features of our products and/or services.

6. Failure to supply personal information

The failure to supply such personal information as may be needed may:

  1. Result in us being unable to provide you with the pharmacy services you require and/or products requested;
  2. Affect our ability to effect the necessary processes relating to the supply of our products and/or services; and/or
  3. Result in us being unable to update you on our latest products, services, promotions, and events.

7. Disclosure of your personal information

Personal data provided to us will be kept confidential pursuant to existing data privacy regulations but you hereby consent and authorize us to provide or disclose your personal information to the following categories of parties:

  1. Companies and/or organizations that act as our agents, contractors and/or service providers for the purpose of fulfilling our obligations to you;
  2. Our channel partners and Affiliates for purposes that are related to collecting and using your personal information to render their services;
  3. Other parties in respect of whom you have previously given your express consent;
  4. Companies and/or organizations that assist us in processing and/or otherwise fulfilling transactions and providing you with products and/or services that you have requested or subscribed for.

8. Direct Marketing

We may use your personal data to provide you with information about our and/or an Affiliate’s services and/or products, which may be of interest to or benefit you, except where otherwise requested or notified by you.

Please note that we will only disclose your personal information only where you have subscribed for particular services of products which require such disclosure and/or where your consent has been obtained. Only affiliates with a data sharing agreement shall be able to obtain this information.

9. Personal data Integrity

We will take all reasonable steps to make sure that the personal information collected, used or disclosed is accurate, complete, not misleading and up-to-date.

10. Personal data security

We will take all reasonable steps to protect the personal information we hold from loss, misuse, modification, unauthorized or accidental access or disclosure, alteration or destruction.

We will not keep personal information for longer than is necessary and will take reasonable steps to destroy or permanently de-identify personal information.

11. Data transfer and sharing to Affiliates

Where we consider it necessary or appropriate for the purposes of data storage or processing or providing any service or product on our behalf to you, we may transfer your personal information to another Affiliate within the Philippines, under conditions of confidentiality and similar levels of security safeguards.

12. Access, Correction, withdrawal and deletion

In accordance with the Act, we may on written request received from you, provide you with access to your personal information and consider a request for correction, withdrawal of consent as regards collection and processing or deletion of that data. In such circumstances, please email your request to our Data Information Controller-

Email: dataprotection@medexpress.com.ph

We will use reasonable endeavor to respond to your request within 30 days from our receipt of your email request.

Please note that in certain situations we may have to withhold access to your personal information, for example where we are unable to confirm your identity.

If we do not receive any email from you within fourteen (14) days of this Notice, we shall presume that you have approved of our continued use of your personal information in accordance with this Notice. However, please rest assured that you will be able to terminate this approval or withdraw your consent at any time.

How to delete your personal data?

Follow these steps:

  • Login to your account.
  • After you logged-in, in the right upper side. Just click your first name and find 'Delete My Personal Data' and click it.
  • When you are on 'Personal Data Deletion', please provide your reason and just click 'Proceed with Deletion'.